CVE-2026-50195Patch(linuxfoundation / containerd)

LOWCVSS 9.9 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch linuxfoundation containerd systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

containerd is an open-source container runtime. Versions prior to 2.3.2, 2.2.5 and 2.1.9 contain a vulnerability in the CRI checkpoint import process where it fails to validate the image references specified within a checkpoint image's configuration. An attacker with permissions to create pods can use a crafted checkpoint image to force containerd to pull a malicious image and assign it an arbitrary local tag, thereby poisoning the node's local image cache. Subsequently, if other pods on the same node attempt to use the poisoned tag with an IfNotPresent (or Never) pull policy, they will unknowingly execute the attacker's malicious image instead of the legitimate one. This can lead to a compromise of the affected pods, allowing the attacker to execute arbitrary code under the victim pod's identity. This issue has been fixed in versions 2.3.2, 2.2.5 and 2.1.9.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-345CWE-829

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • containerd

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 4 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 3d ago at 2 mentions (2026-06-19); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Products
containerd

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-06-19: 2Mentions · 2026-07-01: 1Mentions · 2026-07-18: 1Mentions · 2026-07-26: 1Patch / Workaround · 2026-06-19: 1Patch / Workaround · 2026-07-01: 1Patch / Workaround · 2026-07-26: 1Technical Details · 2026-06-19: 2Technical Details · 2026-07-01: 1Technical Details · 2026-07-26: 106-1907-0107-1807-26
Signal classification3 categories
Patch
360.0%
Disclosure
120.0%
General
120.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-06-192
Disclosure1Patch1
2026-07-011
Patch1
2026-07-181
General1
2026-07-261
Patch1
Full discourse5 posts
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨Critical - containerd CRI Plugin Multiple Vulnerabilities (CVE-2026-50195, CVE-2026-53488, CVE-2026-53492, CVE-2026-53489, CVE-2026-47262) AWS disclosed five flaws in the containerd CRI plugin (v1.7–2.3), the runtime behind EKS, ECS, Fargate, GKE and self-managed Kubernetes. Most are reachable by an attacker who only has permission to create pods on a shared node. The headline bug lets a crafted checkpoint image poison the node's local image cache so other pods unknowingly run the attacker's image — cross-pod code execution. Even nastier: unsanitized image LABEL instructions reach the restart-monitor binary:// logger, giving host-root command execution straight from an image pull, with no checkpoint/restore required. The rest cover CDI annotation smuggling (device/host-mount injection), arbitrary host file read via symlinked log paths, and an image-triggered OOM DoS. 👉Upgrade to containerd 2.3.2 / 2.2.5 / 2.1.9.

    Post summary

    The tweet announces five critical CVEs in containerd CRI, details the attack vectors, and provides upgrade versions to mitigate the issues.

    00100112
    232 followersView on X
  • takenaka hiroya@Joe_Biden_ja
    Patch

    containerdをご利用の方へ、重要な脆弱性CVE-2026-50195について記事を公開しました。CVSS 9.9の深刻度で、共有K8sノードでの越境コード実行リスクがあります。修正バージョンは2.3.2/2.2.5/2.1.9です。早めの対応をご検討ください。 https://cve.autoarticles.net/cve/CVE-2026-50195

    Post summary

    An article announces CVE‑2026‑50195, a containerd vulnerability with a CVSS score of 9.9 that poses a cross‑node code‑execution risk; patch versions 2.3.2/2.2.5/2.1.9 are listed and users are urged to update promptly.

    0000065
    562 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-50195: containerd Checkpoint Import Flaw - What It Means for Your Business and How to Respond https://hubs.li/Q04pYKDl0

    Post summary

    The provided text offers only a headline about CVE‑2026‑50195 for containerd, lacking details on exploitation, patches, or technical depth.

    0000051
    32 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 containerd, Image Cache Poisoning via CRI Checkpoint Import, #CVE-2026-50195 (Critical) -DC-Jun2026-499 https://dailycve.com/containerd-image-cache-poisoning-via-cri-checkpoint-import-cve-2026-50195-critical-dc-jun2026-499/

    Post summary

    An announcement of CVE-2026-50195 for containerd highlights a critical image‑cache poisoning vulnerability via CRI checkpoint import; detailed information can be found at the linked source.

    0000035
    213 followersView on X
  • Can Artuc@canartuc
    Patch

    containerd shipped 2.3.2, 2.2.5, 2.1.9, 2.0.10 and 1.7.33 together, fixing five AWS-reported CRI-plugin CVEs. CVE-2026-50195 lets a poisoned checkpoint import swap an image tag; others reach host-root command execution during restore. Which branch are you still pinned to?

    Post summary

    Containerd has released new versions that address five AWS-reported CRI‑plugin CVEs, including CVE‑2026‑50195 which enables image tag manipulation and host‑root command execution during restore. The focus is on the patch, not on active exploitation or PoC details.

    0000053
    171 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applinuxfoundationcontainerd---

Explore more