MEDIUM GitHub

CVE-2026-53495

containerd: CRI ExecSync Goroutine Leak Leads to Node-Level Denial of Service

### Impact A bug in containerd's CRI ExecSync implementation allows exec probes and lifecycle hooks with background child processes to keep containerd's stdio-drain goroutines indefinitely blocked. Because the I/O drain phase lacks a default timeout or context cancellation handling, repeated ExecSync invocations (like probes) that include long-lived background processes against a container can cause containerd to leak goroutines and host memory. Over time, this resource exhaustion can cause the

Affected Products

References

Published: 2026-09-09 · Source: GitHub · Feed updated: 2026-09-11
This medium severity vulnerability was published on 2026-09-09 via GitHub. Affected: go/github.com/containerd/containerd/v2 < 2.0.12, go/github.com/containerd/containerd < 1.7.35, go/github.com/containerd/containerd/v2 >= 2.2.0, < 2.2.8 and 1 more.
vulnfeed aggregates 13138 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.