Vulnerability Report: GO-2025-3528
- CVE-2024-40635, GHSA-265r-hfxg-fhmg
- Affects: github.com/containerd/containerd, github.com/containerd/containerd/v2
- Published: Mar 18, 2025
- Unreviewed
containerd has an integer overflow in User ID handling in github.com/containerd/containerd
For detailed information about this vulnerability, visit https://github.com/containerd/containerd/security/advisories/GHSA-265r-hfxg-fhmg.
Affected Modules
-
PathGo Versions
-
before v1.6.38, from v1.7.0-beta.0 before v1.7.27
-
before v2.0.4
Aliases
References
- https://github.com/containerd/containerd/security/advisories/GHSA-265r-hfxg-fhmg
- https://github.com/containerd/containerd/commit/05044ec0a9a75232cad458027ca83437aae3f4da
- https://github.com/containerd/containerd/commit/1a43cb6a1035441f9aca8f5666a9b3ef9e70ab20
- https://github.com/containerd/containerd/commit/cf158e884cfe4812a6c371b59e4ea9bc4c46e51a
- https://vuln.go.dev/ID/GO-2025-3528.json
Feedback
This report is unreviewed. It was automatically generated from a third-party source and its details have not been verified by the Go team.
See anything missing or incorrect?
Suggest an edit to this report.