{"id":"CVE-2025-64329","summary":"containerd CRI server: Host memory exhaustion through Attach goroutine leak","details":"containerd is an open-source container runtime. Versions 1.7.28 and below, 2.0.0-beta.0 through 2.0.6, 2.1.0-beta.0 through 2.1.4, and 2.2.0-beta.0 through 2.2.0-rc.1 contain a bug in the CRI Attach implementation where a user can exhaust memory on the host due to goroutine leaks. This issue is fixed in versions 1.7.29, 2.0.7, 2.1.5 and 2.2.0. To workaround this vulnerability, users can set up an admission controller to control accesses to pods/attach resources.","aliases":["GHSA-m6hq-p25p-ffr2","GO-2025-4108"],"modified":"2026-04-17T04:28:32.560423Z","published":"2025-11-07T04:15:09.381Z","related":["CGA-7jqj-8457-jm46","SUSE-SU-2025:21042-1","SUSE-SU-2025:21057-1","SUSE-SU-2025:4072-1","SUSE-SU-2025:4288-1","openSUSE-SU-2025:15726-1"],"database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-401"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/64xxx/CVE-2025-64329.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/64xxx/CVE-2025-64329.json"},{"type":"ADVISORY","url":"https://github.com/containerd/containerd/security/advisories/GHSA-m6hq-p25p-ffr2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-64329"},{"type":"FIX","url":"https://github.com/containerd/containerd/commit/083b53cd6f19b5de7717b0ce92c11bdf95e612df"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/containerd/containerd","events":[{"introduced":"0"},{"fixed":"442cb34bda9a6a0fed82a2ca7cade05c5c749582"},{"introduced":"207ad711eabd375a01713109a8a197d197ff6542"},{"fixed":"4ac6c20c7bbf8177f29e46bbdc658fec02ffb8ad"},{"introduced":"061792f0ecf3684fb30a3a0eb006799b8c6638a7"},{"fixed":"fcd43222d6b07379a4be9786bda52438f0dd16a1"},{"fixed":"083b53cd6f19b5de7717b0ce92c11bdf95e612df"}],"database_specific":{"versions":[{"introduced":"0"},{"fixed":"1.7.29"},{"introduced":"2.0.0"},{"fixed":"2.0.7"},{"introduced":"2.1.0"},{"fixed":"2.1.5"}]}}],"versions":["0.0.2","0.0.3","0.0.4","0.0.5","api/v1.10.0","api/v1.10.0-beta.0","api/v1.10.0-beta.1","api/v1.10.0-rc.0","api/v1.6.0-beta.1","api/v1.6.0-beta.2","api/v1.6.0-beta.3","api/v1.7.19","v0.2.0","v1.0.0","v1.0.0-alpha0","v1.0.0-alpha1","v1.0.0-alpha2","v1.0.0-alpha3","v1.0.0-alpha4","v1.0.0-alpha5","v1.0.0-alpha6","v1.0.0-beta.0","v1.0.0-beta.1","v1.0.0-beta.2","v1.0.0-beta.3","v1.0.0-rc.0","v1.1.0","v1.1.0-rc.0","v1.1.0-rc.1","v1.1.0-rc.2","v1.2.0","v1.2.0-beta.0","v1.2.0-beta.1","v1.2.0-beta.2","v1.2.0-rc.0","v1.2.0-rc.1","v1.2.0-rc.2","v1.3.0","v1.3.0-beta.0","v1.3.0-beta.1","v1.3.0-beta.2","v1.3.0-rc.0","v1.3.0-rc.1","v1.3.0-rc.2","v1.3.0-rc.3","v1.4.0","v1.4.0-beta.0","v1.4.0-beta.1","v1.4.0-beta.2","v1.4.0-rc.0","v1.4.0-rc.1","v1.5.0","v1.5.0-beta.0","v1.5.0-beta.1","v1.5.0-beta.2","v1.5.0-beta.3","v1.5.0-beta.4","v1.5.0-rc.0","v1.5.0-rc.1","v1.5.0-rc.2","v1.5.0-rc.3","v1.6.0","v1.6.0-beta.0","v1.6.0-beta.1","v1.6.0-beta.2","v1.6.0-beta.3","v1.6.0-beta.4","v1.6.0-beta.5","v1.6.0-rc.0","v1.6.0-rc.1","v1.6.0-rc.2","v1.6.0-rc.3","v1.6.0-rc.4","v1.7.0","v1.7.0-beta.0","v1.7.0-beta.1","v1.7.0-beta.2","v1.7.0-beta.3","v1.7.0-beta.4","v1.7.0-rc.0","v1.7.0-rc.1","v1.7.0-rc.2","v1.7.0-rc.3","v1.7.1","v1.7.10","v1.7.11","v1.7.12","v1.7.13","v1.7.14","v1.7.15","v1.7.16","v1.7.17","v1.7.18","v1.7.19","v1.7.2","v1.7.20","v1.7.21","v1.7.22","v1.7.23","v1.7.24","v1.7.25","v1.7.26","v1.7.27","v1.7.28","v1.7.3","v1.7.4","v1.7.5","v1.7.6","v1.7.7","v1.7.8","v1.7.9","v2.0.0","v2.0.1","v2.0.2","v2.0.3","v2.0.4","v2.0.5","v2.0.6","v2.1.0","v2.1.1","v2.1.2","v2.1.3","v2.1.4","v2.2.0-beta.0","v2.2.0-beta.1","v2.2.0-beta.2","v2.2.0-rc.0","v2.2.0-rc.1"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-64329.json","unresolved_ranges":[{"events":[{"introduced":"0"},{"last_affected":"2.2.0-beta0"}]},{"events":[{"introduced":"0"},{"last_affected":"2.2.0-beta1"}]},{"events":[{"introduced":"0"},{"last_affected":"2.2.0-beta2"}]},{"events":[{"introduced":"0"},{"last_affected":"2.2.0-rc0"}]},{"events":[{"introduced":"0"},{"last_affected":"2.2.0-rc1"}]}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}]}