MEDIUM GitHub
CVE-2026-53495
containerd: CRI ExecSync Goroutine Leak Leads to Node-Level Denial of Service
### Impact
A bug in containerd's CRI ExecSync implementation allows exec probes and lifecycle hooks with background child processes to keep containerd's stdio-drain goroutines indefinitely blocked. Because the I/O drain phase lacks a default timeout or context cancellation handling, repeated ExecSync invocations (like probes) that include long-lived background processes against a container can cause containerd to leak goroutines and host memory. Over time, this resource exhaustion can cause the
Affected Products
- go/github.com/containerd/containerd/v2 < 2.0.12
- go/github.com/containerd/containerd < 1.7.35
- go/github.com/containerd/containerd/v2 >= 2.2.0, < 2.2.8
- go/github.com/containerd/containerd/v2 >= 2.3.0, < 2.3.5
References
- https://github.com/advisories/GHSA-7jxh-36q5-gcqv
- https://github.com/containerd/containerd/security/advisories/GHSA-7jxh-36q5-gcqv
- https://github.com/containerd/containerd/releases/tag/v1.7.35
- https://github.com/containerd/containerd/releases/tag/v2.0.12
This medium severity vulnerability was published on 2026-09-09 via GitHub. Affected: go/github.com/containerd/containerd/v2 < 2.0.12, go/github.com/containerd/containerd < 1.7.35, go/github.com/containerd/containerd/v2 >= 2.2.0, < 2.2.8 and 1 more.
vulnfeed aggregates 13138 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.