Resource exhaustion in containerd - CVE-2026-47262
Published: June 19, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in group parsing when creating a container from a maliciously crafted image. A remote user can supply a specially crafted image to cause a denial of service.
Successful exploitation can exhaust memory and trigger an out-of-memory kill of the containerd process, making the runtime API unavailable.
Affected software
openEuler
Fedora
docker-buildkit
docker-buildx
containerd
docker-compose
moby-engine
How to mitigate CVE-2026-47262
docker-buildkit - update to 0.32.1-1.fc45
docker-buildx - update to 0.36.0-1.fc45
containerd - addressed in versions 1.2.0-225, 1.2.0-326, 1.6.22-29
containerd - update to 2.3.2-1.fc45
docker-compose - update to 5.3.0-1.fc45
moby-engine - addressed in versions 29.6.2-1.fc43, 29.6.2-1.fc44, 29.6.2-1.fc45
External References
Related Security Bulletins
- Multiple vulnerabilities in containerd
- Fedora 45 update for docker-compose
- openEuler 24.03 LTS SP1 update for containerd
- openEuler 22.03 LTS SP4 update for containerd
- openEuler 20.03 LTS SP4 update for containerd
- openEuler 24.03 LTS SP3 update for containerd
- Fedora 45 update for moby-engine
- Fedora 44 update for moby-engine
- Fedora 43 update for moby-engine
- openEuler 24.03 LTS SP4 update for containerd
- Fedora 45 update for containerd
- Fedora 45 update for docker-buildx
- Fedora 45 update for docker-buildkit