Time-of-check Time-of-use (TOCTOU) Race Condition in containerd - CVE-2025-47290
Published: May 21, 2025
Vulnerability identifier: #VU109601
CSH Severity: High
CVSS v4: 7.5 [CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-47290
CWE-ID: CWE-367
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to a race condition while unpacking an image during an image pull. A remote attacker can trick the victim into using a specially crafted image and perform arbitrary modifications of the host file system, leading to its compromise.
Affected software
containerd
Robotic Process Automation for Cloud Pak
Fedora
containerd
Robotic Process Automation for Cloud Pak
Fedora
containerd
How to mitigate CVE-2025-47290
Install updates from vendor's website.
containerd - update to 2.1.1
Robotic Process Automation for Cloud Pak - update to 23.0.20.3
containerd - update to 2.1.1-1.fc43
Robotic Process Automation for Cloud Pak - update to 23.0.20.3
containerd - update to 2.1.1-1.fc43