CVE-2025-64329
ADVISORY - githubSummary
Impact
A bug was found in containerd's CRI Attach implementation where a user can exhaust memory on the host due to goroutine leaks.
Repetitive calls of CRI Attach (e.g., kubectl attach) could increase the memory usage of containerd.
Patches
This bug has been fixed in the following containerd versions:
- 2.2.0
- 2.1.5
- 2.0.7
- 1.7.29
Users should update to these versions to resolve the issue.
Workarounds
Set up an admission controller to control accesses to pods/attach resources.
e.g., Validating Admission Policy.
Credits
The containerd project would like to thank @Wheat2018 for responsibly disclosing this issue in accordance with the containerd security policy.
References
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-64329
For more information
If you have any questions or comments about this advisory:
- Open an issue in containerd
- Email us at security@containerd.io
To report a security issue in containerd:
Common Weakness Enumeration (CWE)
Missing Release of Memory after Effective Lifetime
Missing Release of Memory after Effective Lifetime
Missing Reference to Active Allocated Resource
NIST
1.8
CVSS SCORE
6.9mediumGitHub
-
CVSS SCORE
6.9mediumAlpine
-
Debian
-
Ubuntu
1.8
CVSS SCORE
5.5mediumGoLang
-
Amazon
-
CVSS SCORE
N/AmediumRed Hat
2.0
CVSS SCORE
6.5mediumChainguard
CGA-222j-4pcw-447h
-
Chainguard
CGA-22jq-cc27-6722
-
Chainguard
CGA-22wg-w6j4-jj5v
-
Chainguard
CGA-233q-q99x-j59x
-
Chainguard
CGA-243p-mq32-v4wc
-
Chainguard
CGA-25v9-j5h4-gpw8
-
Chainguard
CGA-2849-6v34-w4f6
-
Chainguard
CGA-2fh4-54gx-7fh5
-
Chainguard
CGA-2ghq-fj52-j7mc
-
Chainguard
CGA-2mwv-8f9r-rw69
-
Chainguard
CGA-34pc-f627-8c5x
-
Chainguard
CGA-36fp-f9fv-pqfc
-
Chainguard
CGA-3qx7-37r7-f3rr
-
Chainguard
CGA-3x4x-mfpg-xpxm
-
Chainguard
CGA-4626-p5mf-h9g5
-
Chainguard
CGA-4p3r-x8vx-33rm
-
Chainguard
CGA-4p94-f2r3-x5hw
-
Chainguard
CGA-4w63-rqv9-rf49
-
Chainguard
CGA-535h-qg5r-68g8
-
Chainguard
CGA-55jx-vgxj-w756
-
Chainguard
CGA-58pc-v2rv-m48f
-
Chainguard
CGA-5fhx-h9pj-6m9w
-
Chainguard
CGA-5g8g-w6qq-xj92
-
Chainguard
CGA-5grm-jvq6-6crw
-
Chainguard
CGA-62mq-vg3j-26v3
-
Chainguard
CGA-64fm-44j3-hfvq
-
Chainguard
CGA-64qj-mq8p-487g
-
Chainguard
CGA-65q5-44p5-645m
-
Chainguard
CGA-6fj4-w6q9-jhj2
-
Chainguard
CGA-6m42-2qw7-xmfh
-
Chainguard
CGA-6v33-f3w2-cx8q
-
Chainguard
CGA-6wpx-5qq5-p434
-
Chainguard
CGA-6x25-72gg-xw73
-
Chainguard
CGA-77qr-48v7-cr55
-
Chainguard
CGA-7c9x-gqgf-6w6x
-
Chainguard
CGA-7j6r-x3pf-vvh2
-
Chainguard
CGA-7jqj-8457-jm46
-
Chainguard
CGA-7m4h-xfc9-pfm9
-
Chainguard
CGA-84hf-r865-hjj4
-
Chainguard
CGA-868h-5r93-g3ch
-
Chainguard
CGA-92fm-2fc9-gc23
-
Chainguard
CGA-92xp-59qp-mc8q
-
Chainguard
CGA-96j5-h938-m5hh
-
Chainguard
CGA-96m6-hh3h-7rff
-
Chainguard
CGA-99c9-r2w6-272w
-
Chainguard
CGA-9hch-5x3h-87xq
-
Chainguard
CGA-9mm6-ppq9-4rvg
-
Chainguard
CGA-9p2f-3mm2-q3qj
-
Chainguard
CGA-9v45-vjvp-fv3v
-
Chainguard
CGA-c6cx-vjgq-75g8
-
Chainguard
CGA-c729-7hv9-hcrv
-
Chainguard
CGA-cjf5-wwc3-46mx
-
Chainguard
CGA-cm2r-3mh9-gf37
-
Chainguard
CGA-cpw8-g47x-r278
-
Chainguard
CGA-f4hp-8h73-88mg
-
Chainguard
CGA-f4x9-qm2x-vvq6
-
Chainguard
CGA-ffjx-3pxv-jq26
-
Chainguard
CGA-ffpf-h7jx-m274
-
Chainguard
CGA-fr3h-jchr-3794
-
Chainguard
CGA-g38h-px4j-q5cx
-
Chainguard
CGA-g5r7-xcqq-g675
-
Chainguard
CGA-g87f-w6q8-cwr8
-
Chainguard
CGA-gmwx-6vh7-cx2p
-
Chainguard
CGA-gvv3-2mjf-78v7
-
Chainguard
CGA-gw84-x9v2-p525
-
Chainguard
CGA-h37f-jg57-f6f5
-
Chainguard
CGA-hf83-g645-w4h6
-
Chainguard
CGA-hh7f-q3mw-p28r
-
Chainguard
CGA-j3wh-x2xv-q822
-
Chainguard
CGA-j57p-vr4p-55vg
-
Chainguard
CGA-j59p-5hg2-h8mg
-
Chainguard
CGA-j72v-www7-w8c3
-
Chainguard
CGA-j7w2-h9rh-pc4p
-
Chainguard
CGA-jj89-vvcx-cfjv
-
Chainguard
CGA-jjw6-2vvp-h929
-
Chainguard
CGA-jm56-4mqg-h8cv
-
Chainguard
CGA-m4w8-rrmw-hvg8
-
Chainguard
CGA-m77r-jvjw-vfxr
-
Chainguard
CGA-mpwc-5f7r-6r99
-
Chainguard
CGA-mvq3-6gw4-5rcg
-
Chainguard
CGA-mw2h-wx9f-4vxx
-
Chainguard
CGA-mwww-w887-cxpx
-
Chainguard
CGA-p6pf-882j-v2v7
-
Chainguard
CGA-prhw-m2hp-j46x
-
Chainguard
CGA-q7p6-p2mh-qg7c
-
Chainguard
CGA-qc3w-q374-7vg9
-
Chainguard
CGA-qrw6-5h45-h629
-
Chainguard
CGA-qvwj-ppg5-h8g8
-
Chainguard
CGA-qw9f-hx24-q6f3
-
Chainguard
CGA-r5m7-r98h-w6pv
-
Chainguard
CGA-r8ff-rg95-3p77
-
Chainguard
CGA-rc97-vf96-rfgg
-
Chainguard
CGA-rcf7-826g-pxw4
-
Chainguard
CGA-rcfc-4j7c-jqr4
-
Chainguard
CGA-rffg-p5v8-h9pj
-
Chainguard
CGA-rfj9-j58q-hjx2
-
Chainguard
CGA-rj6w-cp7j-m28q
-
Chainguard
CGA-rm43-cqw8-h9m8
-
Chainguard
CGA-v334-mw6g-qm48
-
Chainguard
CGA-v3m3-38xc-95w6
-
Chainguard
CGA-v5p8-38wq-fvmm
-
Chainguard
CGA-vpmq-2fw8-wq2q
-
Chainguard
CGA-vr64-8rwg-w82m
-
Chainguard
CGA-vv9m-3g77-h6q5
-
Chainguard
CGA-vw6w-vgm5-hw8w
-
Chainguard
CGA-w3gf-7f34-3h73
-
Chainguard
CGA-w6gc-wcp8-j5p6
-
Chainguard
CGA-w9hw-hgr2-2q22
-
Chainguard
CGA-whv5-f6hx-xh63
-
Chainguard
CGA-x6vx-q752-q99j
-
Chainguard
CGA-x7p9-578p-j6c5
-
Chainguard
CGA-xf4w-whcq-5x8r
-
Chainguard
CGA-xfr9-wjjj-c3wf
-
Chainguard
CGA-xgvw-635x-r3wp
-
Chainguard
CGA-xjr4-2w86-v95q
-
Chainguard
CGA-xr8x-qh3v-5553
-
Chainguard
CGA-xw6j-m3m3-2hmc
-
Chainguard
CGA-xwqj-rf29-3cmr
-
Photon
CVE-2025-64329
-
CVSS SCORE
6.2mediumminimos
MINI-2xcx-q8gp-cw8w
-
minimos
MINI-3h9r-ppvf-vc3g
-
minimos
MINI-48wm-grwf-fv24
-
minimos
MINI-4g3v-9xgc-54h6
-
minimos
MINI-5pj7-7mhh-qgf7
-
minimos
MINI-63w6-h6v7-q55x
-
minimos
MINI-7m2q-24x2-3vcc
-
minimos
MINI-7wrp-5jq2-6687
-
minimos
MINI-8jr8-p9mc-qwv7
-
minimos
MINI-8pg2-gfgx-24rm
-
minimos
MINI-9c3r-8389-hv8q
-
minimos
MINI-c9v5-x7cm-w9mq
-
minimos
MINI-f5gc-jw8p-mwrx
-
minimos
MINI-f5mw-h448-vr9m
-
minimos
MINI-fwrw-xxhc-7h2w
-
minimos
MINI-jx8j-2q39-8973
-
minimos
MINI-mfjx-58f8-vpgq
-
minimos
MINI-pg56-g5f8-8j4m
-
minimos
MINI-rwcm-8j3c-v993
-
minimos
MINI-w7h7-8qwp-w5hm
-
minimos
MINI-wjw7-7vx5-c8qc
-
minimos
MINI-xj8x-7833-3433
-