Vulnerability Details CVE-2020-15257
                containerd is an industry-standard container runtime and is available as a daemon for Linux and Windows. In containerd before versions 1.3.9 and 1.4.3, the containerd-shim API is improperly exposed to host network containers. Access controls for the shim’s API socket verified that the connecting process had an effective UID of 0, but did not otherwise restrict access to the abstract Unix domain socket. This would allow malicious containers running in the same network namespace as the shim, with an effective UID of 0 but otherwise reduced privileges, to cause new processes to be run with elevated privileges. This vulnerability has been fixed in containerd 1.3.9 and 1.4.3. Users should update to these versions as soon as they are released. It should be noted that containers started with an old version of containerd-shim should be stopped and restarted, as running containers will continue to be vulnerable even after an upgrade. If you are not providing the ability for untrusted users to start containers in the same network namespace as the shim (typically the "host" network namespace, for example with docker run --net=host or hostNetwork: true in a Kubernetes pod) and run with an effective UID of 0, you are not vulnerable to this issue. If you are running containers with a vulnerable configuration, you can deny access to all abstract sockets with AppArmor by adding a line similar to deny unix addr=@**, to your policy. It is best practice to run containers with a reduced set of privileges, with a non-zero UID, and with isolated namespaces. The containerd maintainers strongly advise against sharing namespaces with the host. Reducing the set of isolation mechanisms used for a container necessarily increases that container's privilege, regardless of what container runtime is used for running that container.
                
                    Exploit prediction scoring system (EPSS) score
                    
                        
                            EPSS Score 0.111
                        
                    
                    
                        
                            EPSS Ranking 93.2%
                        
                    
                 
                
                    CVSS Severity
                    
                        
                            CVSS v3 Score 5.2
                        
                    
                    
                        
                            CVSS v2 Score 3.6
                        
                    
                 
                
                
                
                    
                
                
                    
                        Products affected by CVE-2020-15257
                        
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:linuxfoundation:containerd:-
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:linuxfoundation:containerd:0.0.2
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:linuxfoundation:containerd:0.0.3
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:linuxfoundation:containerd:0.0.4
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:linuxfoundation:containerd:0.0.5
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:linuxfoundation:containerd:0.1.0
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:linuxfoundation:containerd:0.2.0
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:linuxfoundation:containerd:0.2.1
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:linuxfoundation:containerd:0.2.2
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:linuxfoundation:containerd:0.2.3
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:linuxfoundation:containerd:0.2.4
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:linuxfoundation:containerd:0.2.5
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:linuxfoundation:containerd:0.2.6
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:linuxfoundation:containerd:0.2.7
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:linuxfoundation:containerd:0.2.8
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:linuxfoundation:containerd:0.2.9
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:linuxfoundation:containerd:1.0.0
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:linuxfoundation:containerd:1.0.1
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:linuxfoundation:containerd:1.0.2
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:linuxfoundation:containerd:1.0.3
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:linuxfoundation:containerd:1.1.0
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:linuxfoundation:containerd:1.1.1
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:linuxfoundation:containerd:1.1.2
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:linuxfoundation:containerd:1.1.3
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:linuxfoundation:containerd:1.1.4
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:linuxfoundation:containerd:1.1.5
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:linuxfoundation:containerd:1.1.6
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:linuxfoundation:containerd:1.1.7
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:linuxfoundation:containerd:1.1.8
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:linuxfoundation:containerd:1.2.0
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:linuxfoundation:containerd:1.2.1
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:linuxfoundation:containerd:1.2.10
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:linuxfoundation:containerd:1.2.11
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:linuxfoundation:containerd:1.2.12
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:linuxfoundation:containerd:1.2.13
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:linuxfoundation:containerd:1.2.14
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:linuxfoundation:containerd:1.2.2
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:linuxfoundation:containerd:1.2.3
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:linuxfoundation:containerd:1.2.4
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:linuxfoundation:containerd:1.2.5
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:linuxfoundation:containerd:1.2.6
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:linuxfoundation:containerd:1.2.7
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:linuxfoundation:containerd:1.2.8
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:linuxfoundation:containerd:1.2.9
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:linuxfoundation:containerd:1.3.0
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:linuxfoundation:containerd:1.3.1
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:linuxfoundation:containerd:1.3.2
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:linuxfoundation:containerd:1.3.3
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:linuxfoundation:containerd:1.3.4
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:linuxfoundation:containerd:1.3.5
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:linuxfoundation:containerd:1.3.6
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:linuxfoundation:containerd:1.3.7
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:linuxfoundation:containerd:1.3.8
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:linuxfoundation:containerd:1.4.0
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:linuxfoundation:containerd:1.4.1
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:linuxfoundation:containerd:1.4.2
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:o:debian:debian_linux:10.0
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:o:fedoraproject:fedora:33