Integer overflow in containerd - CVE-2024-40635
Published: March 17, 2025
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to integer overflow when handling a UID:GID larger than the maximum 32-bit signed integer. A local user can pass a large user identifier value to the application, trigger an integer overflow and execute arbitrary code on the target system.
Affected software
Guardium Data Security Center (GDSC)
Robotic Process Automation for Cloud Pak
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
Containers Module
openSUSE Leap
Ubuntu
openEuler
Fedora
IBM Concert Software
Netcool Operations Insight
Splunk User Behavior Analytics (UBA)
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
watsonx.data
containerd (Ubuntu package)
golang-github-containerd-containerd-dev (Ubuntu package)
golang-github-docker-containerd-dev (Ubuntu package)
containerd
containerd-ctr
containerd-devel
cri-o1.31
docker-compose
moby-engine
How to mitigate CVE-2024-40635
IBM Concert Software - update to 2.0.0
Netcool Operations Insight - update to 1.6.15
watsonx.data - update to 2.2
Guardium Data Security Center (GDSC) - addressed in versions 3.8.1, 3.8.5
Splunk User Behavior Analytics (UBA) - update to 5.4.3
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.21, 23.0.20.2
containerd (Ubuntu package) - addressed in versions Ubuntu Pro, 1.7.24-0ubuntu1~20.04.2, 1.7.24-0ubuntu1~22.04.2, 1.7.24-0ubuntu1~24.04.2, 2.0.0~rc3-0ubuntu1.1
golang-github-containerd-containerd-dev (Ubuntu package) - addressed in versions Ubuntu Pro, 1.6.12-0ubuntu1~20.04.8, 1.6.12-0ubuntu1~22.04.8
golang-github-docker-containerd-dev (Ubuntu package) - update to Ubuntu Pro
containerd - addressed in versions 1.2.0-219, 1.2.0-321, 1.6.22-16
containerd - update to 1.7.27-1.fc41
containerd-ctr - addressed in versions 1.7.27-16.100.1, 1.7.27-150000.123.1
containerd - addressed in versions 1.7.27-16.100.1, 1.7.27-150000.123.1
containerd-devel - addressed in versions 1.7.27-16.100.1, 1.7.27-150000.123.1
cri-o1.31 - update to 1.31.7-1.fc43
docker-compose - update to 2.36.1-1.fc43
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.1.3
moby-engine - addressed in versions 28.0.2-1.fc43, 28.2.2-1.fc43
External References
- https://github.com/containerd/containerd/security/advisories/GHSA-265r-hfxg-fhmg
- https://github.com/containerd/containerd/commit/1a43cb6a1035441f9aca8f5666a9b3ef9e70ab20
- https://github.com/containerd/containerd/commit/05044ec0a9a75232cad458027ca83437aae3f4da
- https://github.com/containerd/containerd/commit/cf158e884cfe4812a6c371b59e4ea9bc4c46e51a
Related Security Bulletins
- Privilege escalation in Containerd
- Fedora 41 update for containerd
- Fedora 43 update for moby-engine
- openEuler 22.03 LTS SP3 update for containerd
- openEuler 20.03 LTS SP4 update for containerd
- Ubuntu update for containerd
- openEuler 24.03 LTS SP1 update for containerd
- openEuler 24.03 LTS update for containerd
- openEuler 22.03 LTS SP4 update for containerd
- Fedora 43 update for cri-o1.31
- SUSE update for containerd
- SUSE update for containerd
- IBM Watson Speech Services Cartridge update for containerd
- Fedora 43 update for docker-compose
- Fedora 43 update for moby-engine
- Multiple vulnerabilities in IBM Robotic Process Automation for Cloud Pak
- IBM watsonx.data update for containerd
- Splunk User Behavior Analytics (UBA) update for third-party components
- Multiple vulnerabilities in IBM Guardium Data Security Center
- Multiple vulnerabilities in IBM Concert Software
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in IBM Guardium Data Security Center