#VU105799 Integer overflow in containerd - CVE-2024-40635
Published: March 17, 2025
containerd
containerd
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to integer overflow when handling a UID:GID larger than the maximum 32-bit signed integer. A local user can pass a large user identifier value to the application, trigger an integer overflow and execute arbitrary code on the target system.
Remediation
External links
- https://github.com/containerd/containerd/security/advisories/GHSA-265r-hfxg-fhmg
- https://github.com/containerd/containerd/commit/1a43cb6a1035441f9aca8f5666a9b3ef9e70ab20
- https://github.com/containerd/containerd/commit/05044ec0a9a75232cad458027ca83437aae3f4da
- https://github.com/containerd/containerd/commit/cf158e884cfe4812a6c371b59e4ea9bc4c46e51a