Resource exhaustion in containerd - CVE-2026-53495
Published: September 6, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in the containerd CRI plugin ExecSync I/O drain phase when handling ExecSync calls involving long-lived background child processes. A local user can repeatedly invoke ExecSync calls with long-lived background child processes to cause a denial of service.
Only Linux systems with the CRI plugin enabled are affected.