Vulnerability Name: | CVE-2023-25153 (CCN-247777) | ||||||||||||
Assigned: | 2023-02-15 | ||||||||||||
Published: | 2023-02-15 | ||||||||||||
Updated: | 2023-02-24 | ||||||||||||
Summary: | containerd is vulnerable to a denial of service, caused by a memory exhaustion flaw when importing an OCI image. By using a specially-crafted image with a large file, a local attacker could exploit this vulnerability to cause a denial of service condition. | ||||||||||||
CVSS v3 Severity: | 6.2 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) 5.4 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
5.4 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 4.9 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:N/A:C)
| ||||||||||||
Vulnerability Consequences: | Denial of Service | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2023-25153 Source: XF Type: UNKNOWN containerd-cve202325153-dos(247777) Source: CCN Type: containerd GIT Repository OCI image importer memory exhaustion Source: CCN Type: IBM Security Bulletin 6988619 (InfoSphere Information Server) IBM InfoSphere Information Server is affected by multiple vulnerabilities in containerd Source: CCN Type: IBM Security Bulletin 6999781 (Edge Application Manager) IBM Edge Application Manager 4.5.1 addresses multiple security vulnerabilities Source: CCN Type: IBM Security Bulletin 7008407 (Robotic Process Automation for Cloud Pak) Multiple operator framework security vulnerabilities may affect IBM Robotic Process Automation for Cloud Pak Source: CCN Type: IBM Security Bulletin 7009757 (Match 360) ICP Match 360 is vulnerable to the following CVEs Source: CCN Type: IBM Security Bulletin 7009909 (Watson Assistant for Cloud Pak for Data) IBM Watson Assistant for IBM Cloud Pak for Data is vulnerable to containerd security bypass and denial of service vulnerabilities( CVE-2023-25173, CVE-2023-25153) Source: CCN Type: IBM Security Bulletin 7014939 (Cloud Pak for Watson AIOps) Multiple Vulnerabilities in CloudPak for Watson AIOps | ||||||||||||
Vulnerable Configuration: | Configuration CCN 1:![]() | ||||||||||||
Oval Definitions | |||||||||||||
| |||||||||||||
BACK |