blob: 8def49efe9bfeabba278bab2353d8e9b4a9982ac [file] [log] [blame]
id: GO-2022-1147
modules:
- module: github.com/containerd/containerd
versions:
- fixed: 1.5.16
- introduced: 1.6.0
- fixed: 1.6.12
vulnerable_at: 1.6.11
summary: containerd CRI stream server vulnerable to host memory exhaustion via terminal in github.com/containerd/containerd
cves:
- CVE-2022-23471
ghsas:
- GHSA-2qjp-425j-52j9
references:
- advisory: https://github.com/containerd/containerd/security/advisories/GHSA-2qjp-425j-52j9
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2022-23471
- fix: https://github.com/containerd/containerd/commit/241563be06a3de8b6a849414c4e805b68d3bb295
- fix: https://github.com/containerd/containerd/commit/a05d175400b1145e5e6a735a6710579d181e7fb0
- web: https://github.com/containerd/containerd/releases/tag/v1.5.16
- web: https://github.com/containerd/containerd/releases/tag/v1.6.12
- web: https://security.gentoo.org/glsa/202401-31
source:
id: GHSA-2qjp-425j-52j9
created: 2024-08-20T14:52:30.021359-04:00
review_status: UNREVIEWED
unexcluded: EFFECTIVELY_PRIVATE