CVE-2026-53488Disclosure(linuxfoundation / containerd)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch linuxfoundation containerd systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

containerd is an open-source container runtime. In versions prior to 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10 the CRI plugin propagates labels from an image config (LABEL instruction in Dockerfile) to a container without validation. This may result in executing an arbitrary command on the host, via a plugin that consumes container labels for some operations. This issue has been fixed in versions 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • containerd

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 2 mentions (2026-07-01); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Products
containerd

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-06-19: 1Mentions · 2026-07-01: 2Mentions · 2026-07-03: 1Patch / Workaround · 2026-07-01: 1Technical Details · 2026-06-19: 1Technical Details · 2026-07-01: 2Technical Details · 2026-07-03: 106-1907-0107-03
Signal classification1 categories
Disclosure
4100.0%
Referenced assets1 URL
Classification over time
DateTotalLabels
2026-06-191
Disclosure1
2026-07-012
Disclosure2
2026-07-031
Disclosure1
Full discourse4 posts
  • CCB Alert@CCBalert
    Disclosure

    Warning: Critical Improper Input Validation Vulnerability in #containerd. CVE-2026-53488 CVSS: 9.4. This can lead to arbitrary command execution on the host. #Patch #Patch #Patch

    Post summary

    A critical improper input validation issue (CVE-2026-53488) affecting containerd has been disclosed, with a CVSS score of 9.4 and the ability to achieve arbitrary command execution on the host.

    02000354
    7.2K followersView on X
  • Mohi@disismohi
    Disclosure

    Your Dockerfile LABEL instructions can execute arbitrary commands on the host. CVE-2026-53488 in containerd. Here's what to check Friday:

    Post summary

    The post discloses CVE-2026-53488, noting that Dockerfile LABEL instructions allow arbitrary command execution on the host through containerd, without mentioning PoCs, exploits, or patches.

    1000082
    70 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨Critical - containerd CRI Plugin Multiple Vulnerabilities (CVE-2026-50195, CVE-2026-53488, CVE-2026-53492, CVE-2026-53489, CVE-2026-47262) AWS disclosed five flaws in the containerd CRI plugin (v1.7–2.3), the runtime behind EKS, ECS, Fargate, GKE and self-managed Kubernetes. Most are reachable by an attacker who only has permission to create pods on a shared node. The headline bug lets a crafted checkpoint image poison the node's local image cache so other pods unknowingly run the attacker's image — cross-pod code execution. Even nastier: unsanitized image LABEL instructions reach the restart-monitor binary:// logger, giving host-root command execution straight from an image pull, with no checkpoint/restore required. The rest cover CDI annotation smuggling (device/host-mount injection), arbitrary host file read via symlinked log paths, and an image-triggered OOM DoS. 👉Upgrade to containerd 2.3.2 / 2.2.5 / 2.1.9.

    Post summary

    AWS announced five critical vulnerabilities in the containerd CRI plugin that can lead to cross‑pod code execution and host‑root command execution, affecting several Kubernetes platforms. Patches are available by upgrading to specified containerd versions.

    00100112
    232 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 containerd CRI, Image-Config Label Injection, #CVE-2026-53488 (High Severity) -DC-Jun2026-492 https://dailycve.com/containerd-cri-image-config-label-injection-cve-2026-53488-high-severity-dc-jun2026-492/

    Post summary

    The text announces a high‑severity CVE (CVE‑2026‑53488) for containerd CRI involving Image‑Config Label Injection, but offers no details on exploitation, mitigation, or active attacks.

    0000033
    213 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applinuxfoundationcontainerd---

Explore more