CVE-2025-64329: containerd CRI server: Host memory exhaustion through Attach goroutine leak
Impact
A bug was found in containerd's CRI Attach implementation where a user can exhaust memory on the host due to goroutine leaks.
Repetitive calls of CRI Attach (e.g., kubectl attach) could increase the memory usage of containerd.
Patches
This bug has been fixed in the following containerd versions:
2.2.0 2.1.5 2.0.7 1.7.29
Users should update to these versions to resolve the issue.
Workarounds
Set up an admission controller to control accesses to pods/attach resources. e.g., Validating Admission Policy.
Credits
The containerd project would like to thank @Wheat2018 for responsibly disclosing this issue in accordance with the containerd security policy.
References
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-64329
For more information
If you have any questions or comments about this advisory:
Open an issue in containerd Email us at security@containerd.io
To report a security issue in containerd:
Report a new vulnerability
Other sources
containerd CRI server: Host memory exhaustion through Attach goroutine leak
— Microsoft
containerd is an open-source container runtime. Versions 1.7.28 and below, 2.0.0-beta.0 through 2.0.6, 2.1.0-beta.0 through 2.1.4, and 2.2.0-beta.0 through 2.2.0-rc.1 contain a bug in the CRI Attach implementation where a user can exhaust memory on the host due to goroutine leaks. This issue is fixed in versions 1.7.29, 2.0.7, 2.1.5 and 2.2.0. To workaround this vulnerability, users can set up an admission controller to control accesses to pods/attach resources.
— NVD
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64329?
CVE-2025-64329 is considered a moderate severity vulnerability due to potential memory exhaustion on the host.
How do I fix CVE-2025-64329?
To remediate CVE-2025-64329, update containerd to version 2.2.0, 2.1.5, or 2.0.7.
What causes CVE-2025-64329?
CVE-2025-64329 is caused by goroutine leaks in containerd's CRI Attach implementation.
Who is affected by CVE-2025-64329?
Users of containerd versions prior to 2.2.0 and specific versions below 1.7.30 are affected by CVE-2025-64329.
Can CVE-2025-64329 be exploited remotely?
Yes, CVE-2025-64329 can be exploited remotely through repetitive calls to CRI Attach commands.