{"id":"CVE-2021-32760","title":"containerd: pulling and extracting crafted container image may result in Unix file permission changes (CVE-2021-32760)","summary":"A flaw was found in containerd where pulling and extracting a specially-crafted container image can result in Unix file permission changes for existing files in the host’s filesystem. Changes to file permissions can deny access to the expe…","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L","cvssSource":"vendor","cwe":"CWE-281","vendor":"Red Hat","product":"RHOSSM 2.4 for RHEL 8","affected":["3scale_api_management_platform 2","openshift_data_science_rhods","openstack_platform 16.2","cert_manager_operator_for_red_hat_openshift","rhossm_2_4_for_rhel 8"],"patched":["openstack_platform 16.2","rhossm_2_4_for_rhel 8"],"published":"2021-07-19","updated":"2026-09-19","sourceUpdated":"2026-09-19T17:22:46+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-32760.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-32760.json"},{"url":"https://access.redhat.com/security/cve/CVE-2021-32760"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1982681"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-32760"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-32760"},{"url":"https://access.redhat.com/errata/RHSA-2022:2183"},{"url":"https://access.redhat.com/errata/RHSA-2023:5952"},{"url":"https://github.com/containerd/containerd/security/advisories/GHSA-c72p-9xmj-rx3w"},{"url":"https://github.com/containerd/containerd/commit/22e9a70c71eff6507be71955947a611f2ed91e6c"},{"url":"https://github.com/containerd/containerd/commit/7ad08c69e09ee4930a48dbf2aab3cd612458617f"},{"url":"https://github.com/containerd/containerd"},{"url":"https://github.com/containerd/containerd/releases/tag/v1.4.8"},{"url":"https://github.com/containerd/containerd/releases/tag/v1.5.4"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DDMNDPJJTP3J5GOEDB66F6MGXUTRG3Y3"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DDMNDPJJTP3J5GOEDB66F6MGXUTRG3Y3"},{"url":"https://security.gentoo.org/glsa/202401-31"}],"tags":["csaf","vex","red-hat","osv","go"],"epss":0.01595,"epssPercentile":0.74673,"aliases":["GHSA-c72p-9xmj-rx3w","GO-2022-0921"],"ecosystem":"go","scores":{"vendor":5.5,"osv":5},"ingestedAt":"2026-07-09T18:56:36.319Z","slug":"CVE-2021-32760","body":"## Overview\n\nA flaw was found in containerd where pulling and extracting a specially-crafted container image can result in Unix file permission changes for existing files in the host’s filesystem. Changes to file permissions can deny access to the expected owner of the file, widen access to others, or set extended bits like setuid, setgid, and sticky. This bug does not directly allow files to be read, modified, or executed without an additional cooperating process.\n\n## Vendor advisories\n\n- **RHSA-2022:2183** · Red Hat · fixed in: Red Hat OpenStack Platform 16.2 · released 2022-05-11 · [advisory](https://access.redhat.com/errata/RHSA-2022:2183)\n- **RHSA-2023:5952** · Red Hat · fixed in: RHOSSM 2.4 for RHEL 8 · released 2023-10-19 · [advisory](https://access.redhat.com/errata/RHSA-2023:5952)\n- **Red Hat VEX** · Moderate · affected: Red Hat 3scale API Management Platform 2, Red Hat OpenShift Data Science (RHODS), Red Hat OpenStack Platform 16.2, cert-manager Operator for Red Hat OpenShift · no fix planned: Red Hat OpenStack Platform 16.2, Red Hat 3scale API Management Platform 2, Red Hat OpenShift Data Science (RHODS) · updated 2026-09-19 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-32760.json)\n\n**containerd: pulling and extracting crafted container image may result in Unix file permission changes** — rated Moderate by Red Hat. Released 2021-07-19, updated 2026-09-19.\n\nAffected:\n\n- Red Hat 3scale API Management Platform 2\n- Red Hat OpenShift Data Science (RHODS)\n- Red Hat OpenStack Platform 16.2\n- cert-manager Operator for Red Hat OpenShift\n\nFixed:\n\n- Red Hat OpenStack Platform 16.2\n- RHOSSM 2.4 for RHEL 8\n\nNo fix planned:\n\n- Red Hat OpenStack Platform 16.2\n- Red Hat 3scale API Management Platform 2\n- Red Hat OpenShift Data Science (RHODS)\n\nNot affected:\n\n- Red Hat OpenStack Platform 16.2\n- Cost Management Metrics Operator\n- Cryostat 2\n- Logging Subsystem for Red Hat OpenShift\n- Migration Toolkit for Containers\n- Migration Toolkit for Virtualization\n- OpenShift API for Data Protection\n- OpenShift Serverless\n- OpenShift Service Mesh 2\n- Red Hat Advanced Cluster Management for Kubernetes 2\n\n## Remediation\n\nOSP 16.2 Release - OSP Director Operator Containers tech preview https://access.redhat.com/errata/RHSA-2022:2183\nFor details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2023:5952\n\n## Package advisory (CVE-2021-32760)\n\nAffected packages:\n\n- `github.com/containerd/containerd < 1.4.8`\n- `github.com/containerd/containerd >= 1.5.0, < 1.5.4`\n\nPatched in:\n\n- `github.com/containerd/containerd 1.4.8`\n- `github.com/containerd/containerd 1.5.4`\n\nSource: https://osv.dev/vulnerability/GHSA-c72p-9xmj-rx3w","depth":"sunlit","depthScore":31,"depthScoreParts":{"impact":30.3,"likelihood":0.3,"exploitation":0,"ransomware":0},"changes":[{"seq":206379,"id":"CVE-2021-32760","ts":1789663223800,"field":"cvss","old":"5","new":"5.5"}]}