Integer overflow in containerd - CVE-2024-40635

 

Integer overflow in containerd - CVE-2024-40635

Published: March 17, 2025


Vulnerability identifier: #VU105799
CSH Severity: Low
CVSS v4 BT: 5.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2024-40635
CWE-ID: CWE-190
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to integer overflow when handling a UID:GID larger than the maximum 32-bit signed integer. A local user can pass a large user identifier value to the application, trigger an integer overflow and execute arbitrary code on the target system.


Affected software

containerd
Guardium Data Security Center (GDSC)
Robotic Process Automation for Cloud Pak
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
Containers Module
openSUSE Leap
Ubuntu
openEuler
Fedora
IBM Concert Software
Netcool Operations Insight
Splunk User Behavior Analytics (UBA)
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
watsonx.data
containerd (Ubuntu package)
golang-github-containerd-containerd-dev (Ubuntu package)
golang-github-docker-containerd-dev (Ubuntu package)
containerd
containerd-ctr
containerd-devel
cri-o1.31
docker-compose
moby-engine

How to mitigate CVE-2024-40635

Install updates from vendor's website.

containerd - addressed in versions 1.6.38, 1.7.27, 2.0.4
IBM Concert Software - update to 2.0.0
Netcool Operations Insight - update to 1.6.15
watsonx.data - update to 2.2
Guardium Data Security Center (GDSC) - addressed in versions 3.8.1, 3.8.5
Splunk User Behavior Analytics (UBA) - update to 5.4.3
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.21, 23.0.20.2
containerd (Ubuntu package) - addressed in versions Ubuntu Pro, 1.7.24-0ubuntu1~20.04.2, 1.7.24-0ubuntu1~22.04.2, 1.7.24-0ubuntu1~24.04.2, 2.0.0~rc3-0ubuntu1.1
golang-github-containerd-containerd-dev (Ubuntu package) - addressed in versions Ubuntu Pro, 1.6.12-0ubuntu1~20.04.8, 1.6.12-0ubuntu1~22.04.8
golang-github-docker-containerd-dev (Ubuntu package) - update to Ubuntu Pro
containerd - addressed in versions 1.2.0-219, 1.2.0-321, 1.6.22-16
containerd - update to 1.7.27-1.fc41
containerd-ctr - addressed in versions 1.7.27-16.100.1, 1.7.27-150000.123.1
containerd - addressed in versions 1.7.27-16.100.1, 1.7.27-150000.123.1
containerd-devel - addressed in versions 1.7.27-16.100.1, 1.7.27-150000.123.1
cri-o1.31 - update to 1.31.7-1.fc43
docker-compose - update to 2.36.1-1.fc43
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.1.3
moby-engine - addressed in versions 28.0.2-1.fc43, 28.2.2-1.fc43

External References

Related Security Bulletins