---
id: CVE-2024-40635
title: >-
  containerd: containerd has an integer overflow in User ID handling
  (CVE-2024-40635)
summary: >-
  A flaw was found in containerd package. Containers launched with a User set as
  a UID:GID larger than the maximum 32-bit signed integer can cause an overflow
  condition where the container ultimately runs as root (UID 0). This issue
  could ca…
severity: medium
cvss: 4.6
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N'
cvssSource: vendor
cwe: CWE-190
vendor: Red Hat
product: Red Hat Openshift Data Foundation 4.22
affected:
  - assisted_installer_for_red_hat_openshift_container_platform 2
  - cert_manager_operator_for_red_hat_openshift
  - deployment_validation_operator
  - logging_subsystem_for_red_hat_openshift
  - migration_toolkit_for_virtualization
  - multicluster_engine_for_kubernetes
  - network_observability_operator
  - openshift_developer_tools_and_services
  - openshift_lightspeed
  - openshift_serverless
  - openshift_service_mesh 3
  - advanced_cluster_management_for_kubernetes 2
  - advanced_cluster_security 4
  - developer_hub
  - openshift_ai_rhoai
  - openshift_container_platform 4
  - openshift_gitops
  - openshift_sandboxed_containers
  - openshift_virtualization 4
  - trusted_application_pipeline
  - openshift_data_foundation 4.22
patched:
  - openshift_data_foundation 4.22
published: '2025-03-17'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T17:18:00+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-40635.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-40635.json
  - url: 'https://access.redhat.com/security/cve/CVE-2024-40635'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2353043'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2024-40635'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2024-40635'
  - url: >-
      https://github.com/containerd/containerd/commit/05044ec0a9a75232cad458027ca83437aae3f4da
  - url: >-
      https://github.com/containerd/containerd/commit/1a43cb6a1035441f9aca8f5666a9b3ef9e70ab20
  - url: >-
      https://github.com/containerd/containerd/commit/cf158e884cfe4812a6c371b59e4ea9bc4c46e51a
  - url: >-
      https://github.com/containerd/containerd/security/advisories/GHSA-265r-hfxg-fhmg
  - url: 'https://access.redhat.com/errata/RHSA-2026:37387'
  - url: 'https://github.com/containerd/containerd'
  - url: 'https://lists.debian.org/debian-lts-announce/2025/05/msg00005.html'
tags:
  - csaf
  - vex
  - red-hat
  - exploit-available
  - osv
  - go
epss: 0.00294
epssPercentile: 0.19517
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/yen5004/CVE-2024-40635_POC'
  checkedAt: '2026-09-25T08:20:44.125Z'
exploitAvailable: true
aliases:
  - GHSA-265r-hfxg-fhmg
  - GO-2025-3528
ecosystem: go
ingestedAt: '2026-09-12T03:13:01.744Z'
---

## Overview

A flaw was found in containerd package. Containers launched with a User set as a UID:GID larger than the maximum 32-bit signed integer can cause an overflow condition where the container ultimately runs as root (UID 0). This issue could cause unexpected behavior for environments that require containers to run as a non-root user.

## Vendor advisories

- **RHSA-2026:37387** · Red Hat · fixed in: Red Hat Openshift Data Foundation 4.22 · released 2026-07-09 · [advisory](https://access.redhat.com/errata/RHSA-2026:37387)
- **Red Hat VEX** · Moderate · affected: Assisted Installer for Red Hat OpenShift Container Platform 2, cert-manager Operator for Red Hat OpenShift, Deployment Validation Operator, Logging Subsystem for Red Hat OpenShift, Migration Toolkit for Virtualization, Multicluster Engine for Kubernetes, … · no fix planned: Assisted Installer for Red Hat OpenShift Container Platform 2, cert-manager Operator for Red Hat OpenShift, Deployment Validation Operator, Logging Subsystem for Red Hat OpenShift, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-40635.json)

**containerd: containerd has an integer overflow in User ID handling** — rated Moderate by Red Hat. Released 2024-01-01, updated 2026-09-21.

Affected:

- Assisted Installer for Red Hat OpenShift Container Platform 2
- cert-manager Operator for Red Hat OpenShift
- Deployment Validation Operator
- Logging Subsystem for Red Hat OpenShift
- Migration Toolkit for Virtualization
- Multicluster Engine for Kubernetes
- Network Observability Operator
- OpenShift Developer Tools and Services
- OpenShift Lightspeed
- OpenShift Serverless
- OpenShift Service Mesh 3
- Red Hat Advanced Cluster Management for Kubernetes 2
- Red Hat Advanced Cluster Security 4
- Red Hat Developer Hub
- Red Hat OpenShift AI (RHOAI)
- Red Hat OpenShift Container Platform 4
- Red Hat OpenShift GitOps
- Red Hat Openshift Sandboxed Containers
- Red Hat OpenShift Virtualization 4
- Red Hat Trusted Application Pipeline

Fixed:

- Red Hat Openshift Data Foundation 4.22

No fix planned:

- Assisted Installer for Red Hat OpenShift Container Platform 2
- cert-manager Operator for Red Hat OpenShift
- Deployment Validation Operator
- Logging Subsystem for Red Hat OpenShift
- Migration Toolkit for Virtualization
- Multicluster Engine for Kubernetes
- Network Observability Operator
- OpenShift Developer Tools and Services
- OpenShift Lightspeed
- OpenShift Serverless
- OpenShift Service Mesh 3
- Red Hat Advanced Cluster Management for Kubernetes 2
- Red Hat Advanced Cluster Security 4
- Red Hat Developer Hub
- Red Hat OpenShift AI (RHOAI)
- Red Hat OpenShift Container Platform 4
- Red Hat OpenShift GitOps
- Red Hat Openshift Sandboxed Containers
- Red Hat OpenShift Virtualization 4
- Red Hat Trusted Application Pipeline

Not affected:

- Red Hat Openshift Data Foundation 4.22

## Remediation

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

For details on how to apply this update, refer to:

https://docs.redhat.com/en/documentation/red_hat_openshift_data_foundation/4.22/html/updating_openshift_data_foundation/updating-ocs-to-odf_rhodf https://access.redhat.com/errata/RHSA-2026:37387

Workarounds / mitigations:

- To mitigate this vulnerability, ensure that only trusted images are used and that only trusted users have permissions to import images.

To implement the recommended controls in OpenShift:
1. Restrict allowed registries at the cluster level by configuring image.config.openshift.io/cluster with allowedRegistriesForImport and registrySources.allowedRegistries.
2. To find out who can pull/import container images into OpenShift for that namespace Based on RBAC permissions: `oc adm policy who-can cr…

## Package advisory (CVE-2024-40635)

Affected packages:

- `github.com/containerd/containerd/v2 < 2.0.4`
- `github.com/containerd/containerd >= 1.7.0-beta.0, < 1.7.27`
- `github.com/containerd/containerd < 1.6.38`

Patched in:

- `github.com/containerd/containerd/v2 2.0.4`
- `github.com/containerd/containerd 1.7.27`
- `github.com/containerd/containerd 1.6.38`

Source: https://osv.dev/vulnerability/GHSA-265r-hfxg-fhmg
