CVE-2024-25621Incorrect Execution-Assigned Permissions in Containerd

Severity
7.8HIGHNVD
CNA7.3
EPSS
0.0%
top 99.81%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 6
Latest updateJan 29

Description

containerd is an open-source container runtime. Versions 0.1.0 through 1.7.28, 2.0.0-beta.0 through 2.0.6, 2.1.0-beta.0 through 2.1.4 and 2.2.0-beta.0 through 2.2.0-rc.1 have an overly broad default permission vulnerability. Directory paths `/var/lib/containerd`, `/run/containerd/io.containerd.grpc.v1.cri` and `/run/containerd/io.containerd.sandbox.controller.v1.shim` were all created with incorrect permissions. This issue is fixed in versions 1.7.29, 2.0.7, 2.1.5 and 2.2.0. Workarounds include

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages6 packages

CVEListV5containerd/containerd< 1.7.29+3
NVDlinuxfoundation/containerd2.0.02.0.7+3
Gogithub.com/containerd_containerd_v22.1.0-beta.02.1.5+2
Debiancontainerd/containerd< 1.4.13~ds1-1~deb11u6+3

Patches

🔴Vulnerability Details

6
OSV
containerd, containerd-app vulnerabilities2026-01-29
OSV
containerd affected by a local privilege escalation via wide permissions on CRI directory in github.com/containerd/containerd2025-11-17
GHSA
containerd affected by a local privilege escalation via wide permissions on CRI directory2025-11-06
CVEList
containerd affected by a local privilege escalation via wide permissions on CRI directory2025-11-06
OSV
CVE-2024-25621: containerd is an open-source container runtime2025-11-06

📋Vendor Advisories

4
Ubuntu
containerd vulnerabilities2026-01-29
Microsoft
containerd affected by a local privilege escalation via wide permissions on CRI directory2025-11-11
Red Hat
github.com/containerd/containerd: containerd local privilege escalation2025-11-06
Debian
CVE-2024-25621: containerd - containerd is an open-source container runtime. Versions 0.1.0 through 1.7.28, 2...2024

💬Community

1
Bugzilla
CVE-2024-25621 trivy: containerd local privilege escalation [fedora-43]2025-12-04
CVE-2024-25621 — Containerd vulnerability | cvebase