---
id: CVE-2026-107446
title: >-
  containerd overlaybd through 1.0.18 has a do_load_index (LSMT index loading)
  integer overflow (and resultant out-of-bounds heap access) for index_bytes, if
  an untrusted overlaybd blob from a registry is used in a scenario with
  multiple o…
summary: >-
  containerd overlaybd through 1.0.18 has a do_load_index (LSMT index loading)
  integer overflow (and resultant out-of-bounds heap access) for index_bytes, if
  an untrusted overlaybd blob from a registry is used in a scenario with
  multiple o…
severity: medium
cvss: 6.8
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H'
cwe:
  - CWE-190
vendor: containerd
product: overlaybd
affected:
  - overlaybd <= 1.0.18
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T04:17:19.410'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-107446'
references:
  - url: >-
      https://github.com/containerd/overlaybd/blob/58f1508f4c841fe27da428f54d987000f7dae4de/src/image_file.cpp
    label: cve@mitre.org
  - url: >-
      https://github.com/containerd/overlaybd/blob/58f1508f4c841fe27da428f54d987000f7dae4de/src/overlaybd/lsmt/file.cpp
    label: cve@mitre.org
  - url: >-
      https://github.com/containerd/overlaybd/commit/a536e3341c82517268b5ce32375b36faecb1fb40
    label: cve@mitre.org
  - url: >-
      https://github.com/containerd/overlaybd/commit/d80c1790920a17e84da025675530624aee753f1b
    label: cve@mitre.org
  - url: 'https://github.com/containerd/overlaybd/pull/438'
    label: cve@mitre.org
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-08T04:04:32.125Z'
---

## Overview

containerd overlaybd through 1.0.18 has a do_load_index (LSMT index loading) integer overflow (and resultant out-of-bounds heap access) for index_bytes, if an untrusted overlaybd blob from a registry is used in a scenario with multiple overlaybd-backed containers.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
