CVE-2023-25153Medium· 5.5▾ SunlitA flaw was found in containerd. When importing an OCI image, there was no limit on the number of bytes read for certain files. A maliciously crafted image with a large file, where a limit was not applied could cause a denial of service.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 30.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.4%
Last analysed / modified upstream
A flaw was found in containerd. When importing an OCI image, there was no limit on the number of bytes read for certain files. A maliciously crafted image with a large file, where a limit was not applied could cause a denial of service.
containerd: OCI image importer memory exhaustion — rated Moderate by Red Hat. Released 2023-02-15, updated 2026-09-21.
Affected:
Fixed:
No fix planned:
Not affected:
Before applying this update, make sure all previously released errata relevant to your system have been applied.
For details on how to apply this update, refer to:
https://access.redhat.com/articles/11258
For supported configurations, refer to:
https://access.redhat.com/articles/1548993 https://access.redhat.com/errata/RHSA-2026:1536 For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2023:6817 The container images provided by this update can be downloaded from the Red Hat container registry at registry.redhat.io using the "podman pull" command. https://access.redhat.com/errata/RHSA-2026:62115
Affected packages:
github.com/containerd/containerd < 1.5.18github.com/containerd/containerd >= 1.6.0, < 1.6.18Patched in:
github.com/containerd/containerd 1.5.18github.com/containerd/containerd 1.6.18Connected by shared product, vendor, weakness, or advisory.
CVE-2022-23524High· 7.5helm: Denial of service through string value parsing (CVE-2022-23524)
CVE-2022-3064High· 7.5go-yaml: Improve heuristics preventing CPU/memory abuse by parsing malicious or large YAML documents (CVE-2022-3064)
CVE-2026-94449High· 7.5A flaw was found in the SmallRye Fault Tolerance library, which is used by Quarkus to provide strategies like retries and circuit breakers for microservices
CVE-2026-79651High· 7.5A flaw was found in the theme localization endpoints of the keycloak-services component, which is the core service responsible for authentication flows and theme management in Keycloak
CVE-2023-5685High· 7.5A flaw was found in XNIO
CVE-2026-14257High· 7.5brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function (CVE-2026-14257)