Improper Preservation of Permissions in containerd
Published Jan 5, 2022
9.1
CRITICALCVSS 3.1
EPSS 1.68%
Description
containerd is an open source container runtime. On installations using SELinux, such as EL8 (CentOS, RHEL), Fedora, or SUSE MicroOS, with containerd since v1.5.0-beta.0 as the backing container runtime interface (CRI), an unprivileged pod scheduled to the node may bind mount, via hostPath volume, any privileged, regular file on disk for complete read/write access (sans delete). Such is achieved by placing the in-container location of the hostPath volume mount at either `/etc/hosts`, `/etc/hostname`, or `/etc/resolv.conf`. These locations are being relabeled indiscriminately to match the container process-label which effectively elevates permissions for savvy containers that would not normally be able to access privileged host files. This issue has been resolved in version 1.5.9. Users are advised to upgrade as soon as possible.
Affected products
-
- Version >= 1.5.0, < 1.5.9StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Containerd | Containerd | n/a |
|
Configuration 1
- ≥ 1.5.1 · < 1.5.9
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
Configuration 2
- 34
- 35
No data.
OpenShift Developer Tools and Services
ocp-tools-4/jenkins-rhel8
Not affected
Red Hat Advanced Cluster Management for Kubernetes 2
containerd
Not affected
Red Hat Advanced Cluster Management for Kubernetes 2
multicloud-operators-channel-container
Affected
Red Hat Advanced Cluster Management for Kubernetes 2
multicloud-operators-subscription-container
Affected
Red Hat Advanced Cluster Management for Kubernetes 2
multicloud-operators-subscription-release-container
Affected
Red Hat Advanced Cluster Management for Kubernetes 2
multicluster-hub-repo-container
Affected
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/prometheus-rhel9
Affected
Red Hat OpenShift Container Platform 4
cri-o
Not affected
Red Hat OpenShift Container Platform 4
openshift
Affected
Red Hat OpenShift Container Platform 4
openshift-clients
Will not fix
Red Hat OpenStack Platform 16.2
osp-director-provisioner-container
Will not fix
Red Hat OpenStack Platform 16.2
rhosp-rhel8-tech-preview/osp-director-operator
Will not fix
Red Hat OpenStack Platform 16.2
rhosp-rhel8/osp-director-downloader
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| OpenShift Developer Tools and Services | ocp-tools-4/jenkins-rhel8 | Not affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | containerd | Not affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | multicloud-operators-channel-container | Affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | multicloud-operators-subscription-container | Affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | multicloud-operators-subscription-release-container | Affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | multicluster-hub-repo-container | Affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/prometheus-rhel9 | Affected | n/a |
| Red Hat OpenShift Container Platform 4 | cri-o | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift | Affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift-clients | Will not fix | n/a |
| Red Hat OpenStack Platform 16.2 | osp-director-provisioner-container | Will not fix | n/a |
| Red Hat OpenStack Platform 16.2 | rhosp-rhel8-tech-preview/osp-director-operator | Will not fix | n/a |
| Red Hat OpenStack Platform 16.2 | rhosp-rhel8/osp-director-downloader | Will not fix | n/a |
github.com/containerd/containerd
Go
Introduced 1.5.0 Fixed 1.5.9
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/containerd/containerd | 1.5.0 | 1.5.9 |
Remediation
Red Hat statement
Because Red Hat OpenStack Platform's director-operator does not use hostPath volumes, the RHOSP Impact has been rated Low impact and no updates will be provided at this time for its containers. In Red Hat OpenShift Container Platform (OCP) the containerd package is not actually used, but because the containerd API is supported the core OCP components are listed as affected by this CVE and the impact is reduced to Low.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
1 other source (GHSA) ▾
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:S/C:P/I:P/A:P
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
PoCAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Apr 22, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Table of values (13 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 1.68% (0.01682) | 76.12th | v5 (v2026.06.15) |
| Jun 15, 2026 | 1.69% (0.01690) | 74.01th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.14% (0.00139) | 31.35th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.50% (0.00495) | 77.01th | v3 (v2023.03.01) |
| Mar 29, 2024 | 0.50% (0.00495) | 75.80th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.38% (0.00383) | 72.32th | v3 (v2023.03.01) |
| Nov 8, 2023 | 0.38% (0.00383) | 70.01th | v3 (v2023.03.01) |
| Sep 3, 2023 | 0.18% (0.00180) | 54.56th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.14% (0.00141) | 48.02th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.03% (0.01034) | 41.69th | v2 (v2022.01.01) |
| Feb 4, 2022 | 0.95% (0.00950) | 13.46th | v2 (v2022.01.01) |
| Feb 3, 2022 | 1.04% (0.01040) | 28.32th | v5 (v2026.06.15) |
| Jan 6, 2022 | 1.04% (0.01040) | 27.69th | v1 |
References (13)
- https://access.redhat.com/security/cve/CVE-2021-43816 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2044434 Issue Tracking
- https://github.com/advisories/GHSA-mvff-h3cj-wj9c Advisory
- https://github.com/containerd/containerd/commit/a731039238c62be081eb8c31525b988415745eea x_refsource_MISCPatchThird Party Advisory
- https://github.com/containerd/containerd/issues/6194 x_refsource_MISCExploitIssue TrackingThird Party Advisory
- https://github.com/containerd/containerd/security/advisories/GHSA-mvff-h3cj-wj9c x_refsource_CONFIRMThird Party Advisory
- https://github.com/dweomer/containerd/commit/f7f08f0e34fb97392b0d382e58916d6865100299 x_refsource_MISCPatchThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GD5GH7NMK5VJMA2Y5CYB5O5GTPYMWMLX/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MPDIZMI7ZPERSZE2XO265UCK5IWM7CID/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GD5GH7NMK5VJMA2Y5CYB5O5GTPYMWMLX/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MPDIZMI7ZPERSZE2XO265UCK5IWM7CID/
- https://nvd.nist.gov/vuln/detail/CVE-2021-43816
- https://www.cve.org/CVERecord?id=CVE-2021-43816
Change history (0)
No recorded changes yet.