CVE-2026-107446
CVSS Score
6.8
EPSS Score
0.0%
EPSS Percentile
0th
containerd overlaybd through 1.0.18 has a do_load_index (LSMT index loading) integer overflow (and resultant out-of-bounds heap access) for index_bytes, if an untrusted overlaybd blob from a registry is used in a scenario with multiple overlaybd-backed containers.
| CWE | CWE-190 |
| Vendor | containerd |
| Product | overlaybd |
| Published | Oct 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for containerd overlaybd
Be the first to know when new medium vulnerabilities affecting containerd overlaybd are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
None
Integrity
None
Availability
High
Affected Versions
containerd / overlaybd
0 โค 1.0.18
References
github.com: https://github.com/containerd/overlaybd/blob/58f1508f4c841fe27da428f54d987000f7dae4de/src/overlaybd/lsmt/file.cpp github.com: https://github.com/containerd/overlaybd/blob/58f1508f4c841fe27da428f54d987000f7dae4de/src/image_file.cpp github.com: https://github.com/containerd/overlaybd/pull/438 github.com: https://github.com/containerd/overlaybd/commit/a536e3341c82517268b5ce32375b36faecb1fb40 github.com: https://github.com/containerd/overlaybd/commit/d80c1790920a17e84da025675530624aee753f1b