CVE-2026-47262

containerd is an open-source container runtime. Versions prior to 1.7.33, 2.0.10, 2.1.9, 2.2.5 and 2.3.2, contain a vulnerability that allows a maliciously crafted image to cause a Denial of Service (DoS) condition. When creating a container from this image, memory exhaustion occurs, leading to an Out Of Memory (OOM) kill of the containerd process. This renders the container runtime API unavailable and can disrupt clients such as the Docker Engine or Kubernetes control-plane components. This issue has been fixed in versions 1.7.33, 2.0.10, 2.1.9, 2.2.5 and 2.3.2.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:linuxfoundation:containerd:*:*:*:*:*:*:*:*
cpe:2.3:a:linuxfoundation:containerd:*:*:*:*:*:*:*:*
cpe:2.3:a:linuxfoundation:containerd:*:*:*:*:*:*:*:*
cpe:2.3:a:linuxfoundation:containerd:*:*:*:*:*:*:*:*
cpe:2.3:a:linuxfoundation:containerd:*:*:*:*:*:*:*:*

History

02 Jul 2026, 19:40

Type Values Removed Values Added
First Time Linuxfoundation containerd
Linuxfoundation
CPE cpe:2.3:a:linuxfoundation:containerd:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
References () https://github.com/containerd/containerd/security/advisories/GHSA-jpcc-p29g-p8mq - () https://github.com/containerd/containerd/security/advisories/GHSA-jpcc-p29g-p8mq - Vendor Advisory

01 Jul 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-01 19:16

Updated : 2026-07-02 19:40


NVD link : CVE-2026-47262

Mitre link : CVE-2026-47262

CVE.ORG link : CVE-2026-47262


JSON object : View

Products Affected

linuxfoundation

  • containerd
CWE
CWE-400

Uncontrolled Resource Consumption