CVE-2021-32760Medium· 5.5▾ SunlitA flaw was found in containerd where pulling and extracting a specially-crafted container image can result in Unix file permission changes for existing files in the host’s filesystem. Changes to file permissions can deny access to the expe…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 30.3 · likelihood 0.3 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 9.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
1.6%
5 → 5.5
Last analysed / modified upstream
A flaw was found in containerd where pulling and extracting a specially-crafted container image can result in Unix file permission changes for existing files in the host’s filesystem. Changes to file permissions can deny access to the expected owner of the file, widen access to others, or set extended bits like setuid, setgid, and sticky. This bug does not directly allow files to be read, modified, or executed without an additional cooperating process.
containerd: pulling and extracting crafted container image may result in Unix file permission changes — rated Moderate by Red Hat. Released 2021-07-19, updated 2026-09-19.
Affected:
Fixed:
No fix planned:
Not affected:
OSP 16.2 Release - OSP Director Operator Containers tech preview https://access.redhat.com/errata/RHSA-2022:2183 For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2023:5952
Affected packages:
github.com/containerd/containerd < 1.4.8github.com/containerd/containerd >= 1.5.0, < 1.5.4Patched in:
github.com/containerd/containerd 1.4.8github.com/containerd/containerd 1.5.4Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-89638High· 7.0kernel: smb: client: clear setuid/setgid bit on write with cifsacl/modefromsid/posix extensions (CVE-2026-89638)
CVE-2026-61709Medium· 5.3OpenFGA is an authorization and permission engine built for developers
CVE-2026-88016High· 7.1rclone is a command-line program to sync files and directories to and from different cloud storage providers
CVE-2026-39832Critical· 9.1When adding a key to a remote agent constraint extensions such as [email protected] were not serialized in the request
CVE-2026-93433Medium· 5.5A flaw was found in libstoragemgmt
CVE-2026-92382Medium· 4.1An out-of-bounds write flaw was found in usbredir