← Back

CVE-2024-25621

nvd nist
Published: Nov 6, 2025Modified: Jun 17, 2026

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

containerd is an open-source container runtime. Versions 0.1.0 through 1.7.28, 2.0.0-beta.0 through 2.0.6, 2.1.0-beta.0 through 2.1.4 and 2.2.0-beta.0 through 2.2.0-rc.1 have an overly broad default permission vulnerability. Directory paths `/var/lib/containerd`, `/run/containerd/io.containerd.grpc.v1.cri` and `/run/containerd/io.containerd.sandbox.controller.v1.shim` were all created with incorrect permissions. This issue is fixed in versions 1.7.29, 2.0.7, 2.1.5 and 2.2.0. Workarounds include updating system administrator permissions so the host can manually chmod the directories to not have group or world accessible permissions, or to run containerd in rootless mode.

Affected (8)

Containerd
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Linuxfoundation
Before 1.7.29
From 2.0.0 to 2.0.7
From 2.1.0 to 2.1.5
Version 2.2.0 beta0
Version 2.2.0 beta1
Version 2.2.0 beta2
Version 2.2.0 rc0
Version 2.2.0 rc1

References (3)

Timeline

No history available yet.