CVE-2026-53495
Reported by GitHub_M · Published September 14, 2026
containerd is an open-source container runtime. Prior to 1.7.35, 2.0.12, 2.2.8, and 2.3.5, containerd on Linux with the CRI plugin enabled can indefinitely block the drainExecSyncIO goroutine in internal/cri/server/container_execsync.go when CRI ExecSync is used by exec probes or lifecycle hooks that launch long-lived background child processes retaining standard input and output pipes. The input and output drain phase has no default timeout and did not stop when the request context was canceled, so repeated ExecSync invocations can accumulate blocked goroutines and host memory. The resulting resource exhaustion can cause the OOM killer to terminate containerd, leaving the container runtime unavailable until restart. Deployments not using containerd's CRI implementation and containers not running on Linux are not affected. This issue is fixed in versions 1.7.35, 2.0.12, 2.2.8, and 2.3.5.
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| containerd | containerd | < 1.7.35, >= 2.0.0, < 2.0.12, >= 2.2.0, < 2.2.8 |
| chainguard | helm-push | 0, 0 |
| chainguard | docker-cli-buildx | 0 |
| chainguard | chaos-mesh | 0 |
| chainguard | trivy | 0 |
| wolfi | rancher-agent-2.14 | 0, 0, 0 |
| chainguard | envoy-gateway-fips-1.6 | 0 |
| wolfi | newrelic-infrastructure-agent | 0, 0, 0 |
| chainguard | docker-29 | 0 |
| wolfi | k9s | 0, 0, 0 |
| chainguard | headlamp | 0, 0 |
| chainguard | gitlab-rails-ce-fips-19.3 | 0 |
| chainguard | xeol | 0 |
| chainguard | consul-k8s-fips-1.1 | 0 |
| wolfi | k8ssandra-client | 0, 0, 0 |
| wolfi | k8sgpt | 0, 0, 0 |
| chainguard | kubescape-server-fips | 0, 0 |
| wolfi | headlamp | 0, 0, 0 |
| chainguard | harvester | 0, 0 |
| chainguard | datadog-agent-fips-7.80 | 0 |
…and 187 more
Timeline
- Sep 9, 2026 CVE Published
- Sep 14, 2026 CVE Updated
- Sep 15, 2026 EPSS Score
- Sep 18, 2026 EPSS Score
- Sep 19, 2026 Security Advisory
References
- https://github.com/containerd/containerd/security/advisories/GHSA-7jxh-36q5-gcqv x_refsource_CONFIRM
- https://github.com/containerd/containerd/commit/22ccf4314d1fe0834f8e28f10d37d5305ef9880c x_refsource_MISC
- https://github.com/containerd/containerd/commit/5a2a3a759b0d2ad8c821b33c3afc20890daf6d81 x_refsource_MISC
- https://github.com/containerd/containerd/commit/9ec55f024041d0641f6d79841e45c8781141ddaa x_refsource_MISC
- https://github.com/containerd/containerd/commit/eebea8c4c912f44b656c8295c9e6607a19b76650 x_refsource_MISC
- https://github.com/containerd/containerd/commit/ff39a972369e2f12fae561a58d658bbf8f2bc318 x_refsource_MISC
- https://github.com/containerd/containerd/releases/tag/v2.0.12 x_refsource_MISC
- https://github.com/containerd/containerd/releases/tag/v2.2.8 x_refsource_MISC
- https://github.com/containerd/containerd/releases/tag/v2.3.5 x_refsource_MISC
- https://nvd.nist.gov/vuln/detail/CVE-2026-53495 advisory
- https://github.com/advisories/GHSA-7jxh-36q5-gcqv advisory
- https://github.com/containerd/containerd/releases/tag/v1.7.35 url