---
id: CVE-2023-25153
title: 'containerd: OCI image importer memory exhaustion (CVE-2023-25153)'
summary: >-
  A flaw was found in containerd. When importing an OCI image, there was no
  limit on the number of bytes read for certain files. A maliciously crafted
  image with a large file, where a limit was not applied could cause a denial of
  service.
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'
cvssSource: vendor
cwe: CWE-400
vendor: Red Hat
product: Red Hat Ceph Storage 9.0 Tools
affected:
  - ceph_storage 6
  - ceph_storage 7
  - ceph_storage 8
  - ceph_storage_9_0_tools
  - cnv_4_14_for_rhel 9
  - ceph_storage 8.1
patched:
  - ceph_storage_9_0_tools
  - cnv_4_14_for_rhel 9
  - ceph_storage 8.1
published: '2023-02-15'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T17:12:14+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-25153.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-25153.json
  - url: 'https://access.redhat.com/security/cve/CVE-2023-25153'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2174473'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2023-25153'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2023-25153'
  - url: >-
      https://github.com/containerd/containerd/commit/0c314901076a74a7b797a545d2f462285fdbb8c4
  - url: 'https://github.com/containerd/containerd/releases/tag/v1.5.18'
  - url: 'https://github.com/containerd/containerd/releases/tag/v1.6.18'
  - url: >-
      https://github.com/containerd/containerd/security/advisories/GHSA-259w-8hf6-59c2
  - url: 'https://access.redhat.com/errata/RHSA-2026:1536'
  - url: 'https://access.redhat.com/errata/RHSA-2023:6817'
  - url: 'https://access.redhat.com/errata/RHSA-2026:62115'
  - url: 'https://github.com/containerd/containerd'
  - url: 'https://pkg.go.dev/vuln/GO-2023-1573'
tags:
  - csaf
  - vex
  - red-hat
  - osv
  - go
epss: 0.00363
epssPercentile: 0.27361
aliases:
  - GHSA-259w-8hf6-59c2
  - GO-2023-1573
ecosystem: go
ingestedAt: '2026-09-12T03:13:01.744Z'
---

## Overview

A flaw was found in containerd. When importing an OCI image, there was no limit on the number of bytes read for certain files. A maliciously crafted image with a large file, where a limit was not applied could cause a denial of service.

## Vendor advisories

- **RHSA-2026:1536** · Red Hat · fixed in: Red Hat Ceph Storage 9.0 Tools · released 2026-01-29 · [advisory](https://access.redhat.com/errata/RHSA-2026:1536)
- **RHSA-2023:6817** · Red Hat · fixed in: CNV 4.14 for RHEL 9 · released 2023-11-08 · [advisory](https://access.redhat.com/errata/RHSA-2023:6817)
- **RHSA-2026:62115** · Red Hat · fixed in: Red Hat Ceph Storage 8.1 · released 2026-09-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:62115)
- **Red Hat VEX** · Moderate · affected: Red Hat Ceph Storage 6, Red Hat Ceph Storage 7, Red Hat Ceph Storage 8 · no fix planned: Red Hat Ceph Storage 6, Red Hat Ceph Storage 7, Red Hat Ceph Storage 8 · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-25153.json)

**containerd: OCI image importer memory exhaustion** — rated Moderate by Red Hat. Released 2023-02-15, updated 2026-09-21.

Affected:

- Red Hat Ceph Storage 6
- Red Hat Ceph Storage 7
- Red Hat Ceph Storage 8

Fixed:

- Red Hat Ceph Storage 9.0 Tools
- CNV 4.14 for RHEL 9
- Red Hat Ceph Storage 8.1

No fix planned:

- Red Hat Ceph Storage 6
- Red Hat Ceph Storage 7
- Red Hat Ceph Storage 8

Not affected:

- Red Hat Ceph Storage 9.0 Tools
- CNV 4.14 for RHEL 9
- Red Hat Ceph Storage 8.1

## Remediation

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

For supported configurations, refer to:

https://access.redhat.com/articles/1548993 https://access.redhat.com/errata/RHSA-2026:1536
For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2023:6817
The container images provided by this update can be downloaded from the
Red Hat container registry at registry.redhat.io using the "podman pull" command. https://access.redhat.com/errata/RHSA-2026:62115

## Package advisory (CVE-2023-25153)

Affected packages:

- `github.com/containerd/containerd < 1.5.18`
- `github.com/containerd/containerd >= 1.6.0, < 1.6.18`

Patched in:

- `github.com/containerd/containerd 1.5.18`
- `github.com/containerd/containerd 1.6.18`

Source: https://osv.dev/vulnerability/GHSA-259w-8hf6-59c2
