CVE-2026-107446 — containerd overlaybd through 1.0.18 has a do_load_index (LSMT index loading) integer overflow (and resultant out-of-bounds heap access) for index_b…
Description
containerd overlaybd through 1.0.18 has a do_load_index (LSMT index loading) integer overflow (and resultant out-of-bounds heap access) for index_bytes, if an untrusted overlaybd blob from a registry is used in a scenario with multiple overlaybd-backed containers.
CVSS v3.1 base metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:HMedium severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Network
Attack Vector
AC
High
Attack Complexity
PR
None
Privileges Required
UI
None
User Interaction
S
Changed
Scope
C
None
Confidentiality
I
None
Integrity
A
High
Availability
References
- advisory[email protected]https://github.com/containerd/overlaybd/blob/58f1508f4c841fe27da428f54d987000f7dae4de/src/image_file.cpp
- advisory[email protected]https://github.com/containerd/overlaybd/blob/58f1508f4c841fe27da428f54d987000f7dae4de/src/overlaybd/lsmt/file.cpp
- advisory[email protected]https://github.com/containerd/overlaybd/commit/a536e3341c82517268b5ce32375b36faecb1fb40
- advisory[email protected]https://github.com/containerd/overlaybd/commit/d80c1790920a17e84da025675530624aee753f1b
- advisory[email protected]https://github.com/containerd/overlaybd/pull/438
Related threats
same CWE or vendorCVE-2026-107324 — An integer overflow in BSON value-length handling in the MongoDB Go Driver can cause a runtime panic when an application validates or accesses a ma…
CVE-2026-107324 · 5h ago
CVE-2026-105398 — ImageMagick before 7.1.2-31 contains a heap buffer overflow vulnerability that allows attackers to overwrite heap memory by making a crafted call t…
CVE-2026-105398 · 9h ago
CVE-2026-107224 — Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets.
CVE-2026-107224 · 1d ago
CVE-2026-107217 — Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets.
CVE-2026-107217 · 1d ago
CVE-2026-106574 — ImageMagick is free and open-source software used for editing and manipulating digital images.
CVE-2026-106574 · 1d ago
CVE-2026-106571 — ImageMagick is free and open-source software used for editing and manipulating digital images.
CVE-2026-106571 · 1d ago