We found results for “”
CVE-2025-64329
Good to know:
Date: November 6, 2025
containerd is an open-source container runtime. Versions 1.7.28 and below, 2.0.0-beta.0 through 2.0.6, 2.1.0-beta.0 through 2.1.4, and 2.2.0-beta.0 through 2.2.0-rc.1 contain a bug in the CRI Attach implementation where a user can exhaust memory on the host due to goroutine leaks. This issue is fixed in versions 1.7.29, 2.0.7, 2.1.5 and 2.2.0. To workaround this vulnerability, users can set up an admission controller to control accesses to pods/attach resources.
Severity Score
Related Resources (5)
Severity Score
Weakness Type (CWE)
Missing Release of Memory after Effective Lifetime
CWE-401Top Fix
Upgrade Version
Upgrade to version github.com/containerd/containerd - v1.7.29;github.com/containerd/containerd/v2 - v2.0.7;github.com/containerd/containerd/v2 - v2.1.5;github.com/containerd/containerd/v2 - v2.2.0;https://github.com/containerd/containerd.git - v2.2.0;https://github.com/containerd/containerd.git - v2.1.5;https://github.com/containerd/containerd.git - v2.0.7;https://github.com/containerd/containerd.git - v1.7.29
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | LOCAL |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | NONE |
| User Interaction (UI): | NONE |
| Scope (S): | UNCHANGED |
| Confidentiality (C): | NONE |
| Integrity (I): | NONE |
| Availability (A): | HIGH |
Vulnerabilities
Projects
Contact Us


