Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
146377 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.1.10.2025.0130
Categoría:Mageia Linux Local Security Checks
Título:Mageia: Security Advisory (MGASA-2025-0130)
Resumen:The remote host is missing an update for the 'docker-containerd' package(s) announced via the MGASA-2025-0130 advisory.
Descripción:Summary:
The remote host is missing an update for the 'docker-containerd' package(s) announced via the MGASA-2025-0130 advisory.

Vulnerability Insight:
containerd is an open-source container runtime. A bug was found in
containerd prior to versions 1.6.38, 1.7.27, and 2.0.4 where containers
launched with a User set as a `UID:GID` larger than the maximum 32-bit
signed integer can cause an overflow condition where the container
ultimately runs as root (UID 0). This could cause unexpected behavior
for environments that require containers to run as a non-root user. This
bug has been fixed in containerd 1.6.38, 1.7.27, and 2.04. As a
workaround, ensure that only trusted images are used and that only
trusted users have permissions to import images.

Affected Software/OS:
'docker-containerd' package(s) on Mageia 9.

Solution:
Please install the updated package(s).

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2024-40635
CopyrightCopyright (C) 2025 Greenbone AG

Esta es sólo una de 146377 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.