Back

MEDIUM

Containerd has image-pull DoS via crafted OCI index graph amplification

Published Sep 25, 2026

Description

containerd is an open-source container runtime. Prior to versions 1.7.36, 2.0.13, 2.2.9, 2.3.6, and 2.4.1, a crafted OCI index graph can force very high CPU/memory usage during PullImage (before container start), causing long ContainerCreating stalls and, at larger sizes, node/runtime instability. Versions 1.7.36, 2.0.13, 2.2.9, 2.3.6, and 2.4.1 fix the issue.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Sep 25, 2026
Updated Sep 28, 2026
Reserved Jun 9, 2026
CISA Vulnrichment
Updated Sep 28, 2026
NVD
Status Awaiting Analysis
Modified Sep 25, 2026
Red Hat
Severity n/a
Public date n/a
GHSA-PG57-6JWG-Q645