Input validation error in containerd - CVE-2026-53488
Published: June 19, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary commands on the host.
The vulnerability exists due to improper input validation in the containerd CRI plugin when propagating image configuration labels to containers. A remote attacker can supply a crafted image with malicious labels to execute arbitrary commands on the host.
Exploitation requires a plugin that consumes container labels for some operations.
Affected software
openEuler
Fedora
containerd
Multicluster Engine for Kubernetes
How to mitigate CVE-2026-53488
containerd - addressed in versions 1.2.0-225, 1.2.0-326, 1.6.22-29
containerd - update to 2.3.2-1.fc45
Multicluster Engine for Kubernetes - update to 2.10.4
External References
Related Security Bulletins
- Multiple vulnerabilities in containerd
- openEuler 24.03 LTS SP1 update for containerd
- openEuler 22.03 LTS SP4 update for containerd
- openEuler 20.03 LTS SP4 update for containerd
- openEuler 24.03 LTS SP3 update for containerd
- Input validation error in Multicluster Engine for Kubernetes 2.10
- openEuler 24.03 LTS SP4 update for containerd
- Fedora 45 update for containerd