openSUSE-SU-2026:21213-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21213-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2026:21213-1
Upstream
CVE (10)
Related
Published
2026-07-02T09:47:31Z
Modified
2026-07-03T11:00:06Z
Summary
Security update for containerd
Details

This update for containerd fixes the following issues

Update to 1.7.33:

  • CVE-2024-25621: overly broad default permission vulnerability (bsc#1253126).
  • CVE-2025-64329: goroutine leaks can lead to memory exhaustion on the host (bsc#1253132).
  • CVE-2026-33186: google.golang.org/grpc: authorization bypass due to improper validation of the HTTP/2 :path pseudo- header (bsc#1260296).
  • CVE-2026-33814: golang.org/x/net/http2: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE (bsc#1265794).
  • CVE-2026-34986: github.com/go-jose/go-jose/v4,github.com/go-jose/go-jose/v3: crafted JWE input with a missing encrypted key can lead to a denial of service (bsc#1262948).
  • CVE-2026-35469: github.com/moby/spdystream: memory amplification in SPDY frame parsing leads to denial of service (bsc#1262266).
  • CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266640).
  • CVE-2026-46680: containerd user ID handling bypass allows runAsNonRoot evasion (bsc#1268355).
  • CVE-2026-47262: Denial of Service (DoS) condition via a maliciously crafted image (bsc#1268441).
  • CVE-2026-53488: CRI plugin propagates labels from an image config to a container without validation (bsc#1268430).

Changes for containerd:

References

Affected packages

openSUSE:Leap 16.0 / containerd

Package

Name
containerd
Purl
pkg:rpm/opensuse/containerd&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.7.33-160000.1.1

Ecosystem specific

{
    "binaries":  [
        {
            "containerd":  "1.7.33-160000.1.1",
            "containerd-ctr":  "1.7.33-160000.1.1",
            "containerd-devel":  "1.7.33-160000.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21213-1.json"