{"id":"CVE-2023-25153","title":"containerd: OCI image importer memory exhaustion (CVE-2023-25153)","summary":"A flaw was found in containerd. When importing an OCI image, there was no limit on the number of bytes read for certain files. A maliciously crafted image with a large file, where a limit was not applied could cause a denial of service.","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":"CWE-400","vendor":"Red Hat","product":"Red Hat Ceph Storage 9.0 Tools","affected":["ceph_storage 6","ceph_storage 7","ceph_storage 8","ceph_storage_9_0_tools","cnv_4_14_for_rhel 9","ceph_storage 8.1"],"patched":["ceph_storage_9_0_tools","cnv_4_14_for_rhel 9","ceph_storage 8.1"],"published":"2023-02-15","updated":"2026-09-21","sourceUpdated":"2026-09-21T17:12:14+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-25153.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-25153.json"},{"url":"https://access.redhat.com/security/cve/CVE-2023-25153"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2174473"},{"url":"https://www.cve.org/CVERecord?id=CVE-2023-25153"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-25153"},{"url":"https://github.com/containerd/containerd/commit/0c314901076a74a7b797a545d2f462285fdbb8c4"},{"url":"https://github.com/containerd/containerd/releases/tag/v1.5.18"},{"url":"https://github.com/containerd/containerd/releases/tag/v1.6.18"},{"url":"https://github.com/containerd/containerd/security/advisories/GHSA-259w-8hf6-59c2"},{"url":"https://access.redhat.com/errata/RHSA-2026:1536"},{"url":"https://access.redhat.com/errata/RHSA-2023:6817"},{"url":"https://access.redhat.com/errata/RHSA-2026:62115"},{"url":"https://github.com/containerd/containerd"},{"url":"https://pkg.go.dev/vuln/GO-2023-1573"}],"tags":["csaf","vex","red-hat","osv","go"],"epss":0.00363,"epssPercentile":0.30153,"aliases":["GHSA-259w-8hf6-59c2","GO-2023-1573"],"ecosystem":"go","ingestedAt":"2026-09-12T03:13:01.744Z","slug":"CVE-2023-25153","body":"## Overview\n\nA flaw was found in containerd. When importing an OCI image, there was no limit on the number of bytes read for certain files. A maliciously crafted image with a large file, where a limit was not applied could cause a denial of service.\n\n## Vendor advisories\n\n- **RHSA-2026:1536** · Red Hat · fixed in: Red Hat Ceph Storage 9.0 Tools · released 2026-01-29 · [advisory](https://access.redhat.com/errata/RHSA-2026:1536)\n- **RHSA-2023:6817** · Red Hat · fixed in: CNV 4.14 for RHEL 9 · released 2023-11-08 · [advisory](https://access.redhat.com/errata/RHSA-2023:6817)\n- **RHSA-2026:62115** · Red Hat · fixed in: Red Hat Ceph Storage 8.1 · released 2026-09-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:62115)\n- **Red Hat VEX** · Moderate · affected: Red Hat Ceph Storage 6, Red Hat Ceph Storage 7, Red Hat Ceph Storage 8 · no fix planned: Red Hat Ceph Storage 6, Red Hat Ceph Storage 7, Red Hat Ceph Storage 8 · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-25153.json)\n\n**containerd: OCI image importer memory exhaustion** — rated Moderate by Red Hat. Released 2023-02-15, updated 2026-09-21.\n\nAffected:\n\n- Red Hat Ceph Storage 6\n- Red Hat Ceph Storage 7\n- Red Hat Ceph Storage 8\n\nFixed:\n\n- Red Hat Ceph Storage 9.0 Tools\n- CNV 4.14 for RHEL 9\n- Red Hat Ceph Storage 8.1\n\nNo fix planned:\n\n- Red Hat Ceph Storage 6\n- Red Hat Ceph Storage 7\n- Red Hat Ceph Storage 8\n\nNot affected:\n\n- Red Hat Ceph Storage 9.0 Tools\n- CNV 4.14 for RHEL 9\n- Red Hat Ceph Storage 8.1\n\n## Remediation\n\nBefore applying this update, make sure all previously released errata\nrelevant to your system have been applied.\n\nFor details on how to apply this update, refer to:\n\nhttps://access.redhat.com/articles/11258\n\nFor supported configurations, refer to:\n\nhttps://access.redhat.com/articles/1548993 https://access.redhat.com/errata/RHSA-2026:1536\nFor details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2023:6817\nThe container images provided by this update can be downloaded from the\nRed Hat container registry at registry.redhat.io using the \"podman pull\" command. https://access.redhat.com/errata/RHSA-2026:62115\n\n## Package advisory (CVE-2023-25153)\n\nAffected packages:\n\n- `github.com/containerd/containerd < 1.5.18`\n- `github.com/containerd/containerd >= 1.6.0, < 1.6.18`\n\nPatched in:\n\n- `github.com/containerd/containerd 1.5.18`\n- `github.com/containerd/containerd 1.6.18`\n\nSource: https://osv.dev/vulnerability/GHSA-259w-8hf6-59c2","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}