← Vulnerability feed

Vulnerability record · CVE-2023-25173 · published 16 February 2023

CVE-2023-25173: Linuxfoundation containerd incorrect authorization vulnerability

Linuxfoundation · Containerd

containerd is an open source container runtime. A bug was found in containerd prior to versions 1.6.18 and 1.5.18 where supplementary groups are not set up properly inside a container. If an attacker has direct access to a container and manipulates their supplementary group access, they may be able to use supplementary group access to bypass primary group restrictions in some cases, potentially gaining access to sensitive information or gaining the ability to execute code in that container. Downstream applications that use the containerd client library may be affected as well. This bug has been fixed in containerd v1.6.18 and v.1.5.18. Users should update to these versions and recreate containers to resolve this issue. Users who rely on a downstream application that uses containerd's client library should check that application for a separate advisory and instructions. As a workaround, ensure that the `"USER $USERNAME"` Dockerfile instruction is not used. Instead, set the container entrypoint to a value similar to `ENTRYPOINT ["su", "-", "user"]` to allow `su` to properly set up supplementary groups.

7.8 CVSS 3.1 High EPSS 0.54% · top 56.7% CWE-863 · Incorrect authorization
7.8CVSS 3.1 base score
0.54%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
24References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

containerd is an open source container runtime. A bug was found in containerd prior to versions 1.6.18 and 1.5.18 where supplementary groups are not set up properly inside a container. If an attacker has direct access to a container and manipulates their supplementary group access, they may be able to use supplementary group access to bypass primary group restrictions in some cases, potentially gaining access to sensitive information or gaining the ability to execute code in that container. Downstream applications that use the containerd client library may be affected as well. This bug has been fixed in containerd v1.6.18 and v.1.5.18. Users should update to these versions and recreate containers to resolve this issue. Users who rely on a downstream application that uses containerd's client library should check that application for a separate advisory and instructions. As a workaround, ensure that the `"USER $USERNAME"` Dockerfile instruction is not used. Instead, set the container entrypoint to a value similar to `ENTRYPOINT ["su", "-", "user"]` to allow `su` to properly set up supplementary groups.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/advisories/GHSA-4wjj-jwc9-2x96 Not Applicable
https://github.com/advisories/GHSA-fjm8-m7m6-2fjp Not Applicable
https://github.com/advisories/GHSA-phjr-8j92-w5v7 Not Applicable
https://github.com/containerd/containerd/commit/133f6bb6cd827ce35a5fb279c1ead12b9d21460a Patch
https://github.com/containerd/containerd/releases/tag/v1.5.18 Release Notes
https://github.com/containerd/containerd/releases/tag/v1.6.18 Release Notes
https://github.com/containerd/containerd/security/advisories/GHSA-hmfx-3pcx-653p MitigationVendor Advisory
https://github.com/moby/moby/security/advisories/GHSA-rc4r-wh2q-q6c4 Not Applicable
https://lists.fedoraproject.org/archives/list/[email protected]/message/LYZOKMMVX4SIEHPJW3SJUQGMO
https://lists.fedoraproject.org/archives/list/[email protected]/message/XNF4OLYZRQE75EB5TW5N42FSX
https://lists.fedoraproject.org/archives/list/[email protected]/message/ZTE4ITXXPIWZEQ4HYQCB6N6GZ
https://www.benthamsgaze.org/2022/08/22/vulnerability-in-linux-containers-investigation-and-mitigation/ ExploitThird Party Advisory
https://github.com/advisories/GHSA-4wjj-jwc9-2x96 Not Applicable
https://github.com/advisories/GHSA-fjm8-m7m6-2fjp Not Applicable
https://github.com/advisories/GHSA-phjr-8j92-w5v7 Not Applicable
https://github.com/containerd/containerd/commit/133f6bb6cd827ce35a5fb279c1ead12b9d21460a Patch
https://github.com/containerd/containerd/releases/tag/v1.5.18 Release Notes
https://github.com/containerd/containerd/releases/tag/v1.6.18 Release Notes
https://github.com/containerd/containerd/security/advisories/GHSA-hmfx-3pcx-653p MitigationVendor Advisory
https://github.com/moby/moby/security/advisories/GHSA-rc4r-wh2q-q6c4 Not Applicable
https://lists.fedoraproject.org/archives/list/[email protected]/message/LYZOKMMVX4SIEHPJW3SJUQGMO
https://lists.fedoraproject.org/archives/list/[email protected]/message/XNF4OLYZRQE75EB5TW5N42FSX
https://lists.fedoraproject.org/archives/list/[email protected]/message/ZTE4ITXXPIWZEQ4HYQCB6N6GZ
https://www.benthamsgaze.org/2022/08/22/vulnerability-in-linux-containers-investigation-and-mitigation/ ExploitThird Party Advisory

Track CVE-2023-25173 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.4CVE-2026-53488Linuxfoundation containerd improper input validation vulnerabilitycontainerd is an open-source container runtime. In versions prior to 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10 the CRI plugin propagates labels from an…EPSS 0.16%9.1CVE-2021-43816Linuxfoundation containerd vulnerabilitycontainerd is an open source container runtime. On installations using SELinux, such as EL8 (CentOS, RHEL), Fedora, or SUSE MicroOS, with containerd …EPSS 1.7%8.4CVE-2026-53492Linuxfoundation containerd improper input validation vulnerabilitycontainerd is an open-source container runtime. In Versions prior to 2.3.2, 2.2.5 and 2.1.9, the CRI implementation improperly trusts Container Devic…EPSS 0.35%8.2CVE-2026-53489Linuxfoundation containerd vulnerabilitycontainerd is an open-source container runtime. Versions prior to 2.3.2, 2.2.5 and 2.1.9 contain a bug where the CRI plugin restores container.log fr…EPSS 0.17%7.8CVE-2024-25621Linuxfoundation containerd vulnerabilitycontainerd is an open-source container runtime. Versions 0.1.0 through 1.7.28, 2.0.0-beta.0 through 2.0.6, 2.1.0-beta.0 through 2.1.4 and 2.2.0-beta.…EPSS 0.16%7.8CVE-2024-40635Linuxfoundation containerd integer overflow vulnerabilitycontainerd is an open-source container runtime. A bug was found in containerd prior to versions 1.6.38, 1.7.27, and 2.0.4 where containers launched w…EPSS 0.29%7.8CVE-2021-41103Linuxfoundation containerd path traversal vulnerabilitycontainerd is an open source container runtime with an emphasis on simplicity, robustness and portability. A bug was found in containerd where contai…EPSS 0.52%7.6CVE-2025-47290Linuxfoundation containerd toctou race condition vulnerabilitycontainerd is a container runtime. A time-of-check to time-of-use (TOCTOU) vulnerability was found in containerd v2.1.0. While unpacking an image dur…EPSS 0.50%

Source: NIST National Vulnerability Database (record CVE-2023-25173), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.