{"id":"AZL-105123","summary":"CVE-2026-53493 affecting package containerd2 2.3.4-1","details":"containerd is an open-source container runtime. Prior to versions 1.7.36, 2.0.13, 2.2.9, 2.3.6, and 2.4.1, a crafted OCI index graph can force very high CPU/memory usage during PullImage (before container start), causing long ContainerCreating stalls and, at larger sizes, node/runtime instability. Versions 1.7.36, 2.0.13, 2.2.9, 2.3.6, and 2.4.1 fix the issue.","modified":"2026-10-03T05:35:10Z","published":"2026-09-25T01:16:48Z","upstream":["CVE-2026-53493"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53493"}],"affected":[{"package":{"name":"containerd2","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/containerd2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"2.3.4-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-105123.json"}}],"schema_version":"1.9.0"}