========================================================================== Ubuntu Security Notice USN-7374-1 March 26, 2025 containerd vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: containerd could be made to behave unexpectedly. Software Description: - containerd-app: open and reliable container runtime - containerd: open and reliable container runtime library Details: Benjamin Koltermann discovered that containerd incorrectly handled large user id values. This could result in containers possibly being run as root, contrary to expectations. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.10   containerd                      2.0.0~rc3-0ubuntu1.1 Ubuntu 24.04 LTS   containerd                      1.7.24-0ubuntu1~24.04.2   golang-github-containerd-containerd-dev 1.6.24~ds1-1ubuntu1.2+esm1                                   Available with Ubuntu Pro Ubuntu 22.04 LTS   containerd                      1.7.24-0ubuntu1~22.04.2   golang-github-containerd-containerd-dev  1.6.12-0ubuntu1~22.04.8 Ubuntu 20.04 LTS   containerd                      1.7.24-0ubuntu1~20.04.2   golang-github-containerd-containerd-dev  1.6.12-0ubuntu1~20.04.8 Ubuntu 18.04 LTS   containerd                      1.6.12-0ubuntu1~18.04.1+esm2                                   Available with Ubuntu Pro   golang-github-containerd-containerd-dev 1.6.12-0ubuntu1~18.04.1+esm2                                   Available with Ubuntu Pro Ubuntu 16.04 LTS   containerd                      1.2.6-0ubuntu1~16.04.6+esm5                                   Available with Ubuntu Pro   golang-github-docker-containerd-dev  1.2.6-0ubuntu1~16.04.6+esm5                                   Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References:   https://ubuntu.com/security/notices/USN-7374-1   CVE-2024-40635 Package Information: https://launchpad.net/ubuntu/+source/containerd-app/2.0.0~rc3-0ubuntu1.1 https://launchpad.net/ubuntu/+source/containerd/1.6.12-0ubuntu1~22.04.8 https://launchpad.net/ubuntu/+source/containerd-app/1.7.24-0ubuntu1~22.04.2 https://launchpad.net/ubuntu/+source/containerd/1.6.12-0ubuntu1~20.04.8 https://launchpad.net/ubuntu/+source/containerd-app/1.7.24-0ubuntu1~20.04.2