CVE-2026-46680Disclosure(linuxfoundation / containerd)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch linuxfoundation containerd systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

containerd is an open-source container runtime. In versions prior to 1.7.32, 2.0.9, 2.2.4 and 2.3.1, containers launched with a numeric User directive that cannot be parsed as a 32-bit integer are incorrectly treated as a username, leading to runAsNonRoot evasion. If a crafted image provides an /etc/passwd file mapping this large numeric string to root, the container ultimately runs as root (UID 0). This allows the Kubernetes runAsNonRoot restriction to be bypassed, causing unexpected behavior for environments that require containers to run as a non-root user. This issue has been fixed in versions 1.7.32, 2.0.9, 2.2.4 and 2.3.1.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • containerd

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-05-22); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Products
containerd

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-05-22: 1Mentions · 2026-06-09: 1Mentions · 2026-07-03: 1Patch / Workaround · 2026-06-09: 1Technical Details · 2026-05-22: 1Technical Details · 2026-07-03: 105-2206-0907-03
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-221
Disclosure1
2026-06-091
Patch1
2026-07-031
Disclosure1
Full discourse3 posts
  • Mohi@disismohi
    Disclosure

    CVE-2026-46680: containerd lets you bypass runAsNonRoot by exploiting integer overflow in User directive parsing. You end up as root even when Kubernetes policy says you can't. Here's how it works:

    Post summary

    CVE-2026-46680 is disclosed as an integer‑overflow flaw in containerd’s User directive parsing that can bypass runAsNonRoot restrictions, enabling privilege escalation to root.

    1001077
    70 followersView on X
  • Mario Fahlandt 🦊@mfahlandt
    Patch

    🛡️ Cloud Native Security Updates (Week 24, 2026). Envoy v1.38.1+ mitigates CVE-2026-47774. containerd v2.1.8 fixes CVE-2026-46680. Longhorn v1.12.0: V2 Data Engine GA. https://lwcn.dev/newsletter/2026-week-24/

    Post summary

    The note announces that specific updates of Envoy and containerd now mitigate CVE-2026-47774 and CVE-2026-46680, providing patch information.

    0000060
    501 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 containerd, Input Validation Error, #CVE-2026-46680 (High) https://dailycve.com/containerd-input-validation-error-cve-2026-46680-high/

    Post summary

    The post announces a high‑severity input validation error in containerd (CVE‑2026‑46680) but does not provide evidence of exploitation, PoC, or remediation details.

    0000052
    207 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applinuxfoundationcontainerd---

Explore more