logo

CVE-2020-15275: New Vulnerability Exploits containerd-shim API

ID: 17fc4678-0c52-5a71-852d-d8effc1ee1cf

STIX ID: report--17fc4678-0c52-5a71-852d-d8effc1ee1cf

Feed Name: Aqua Security Blog

Threat Score
70/100

Date Published: 2020-12-17

Date Updated: 2026-04-26

...
...

This advisory describes a privilege-escalation vulnerability in containerd's shim (CVE-2020-15257) where abstract namespace Unix domain sockets are permissionless; containers run with host networking and UID 0 can connect to per-container shim sockets and call Create/Start to spawn privileged containers and gain root on the host. The report explains the root cause, demonstrates how sockets appear, outlines exploitation vectors, provides a detection command, and recommends mitigations (upgrade containerd to v1.4.3/v1.3.9, run containers as non-root, and use AppArmor to deny abstract sockets).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.