Integer Overflow Vulnerability in overlaybd Container Storage by containerd
CVE-2026-107446

6.8MEDIUM

Key Information:

Vendor

Containerd

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-107446?

The overlaybd component of containerd version 1.0.18 presents a vulnerability involving integer overflow during the loading of LSMT indexes. When untrusted overlaybd blobs from a registry are utilized across multiple overlaybd-backed containers, the vulnerability allows for out-of-bounds heap access. This could potentially lead to unauthorized access or manipulation of sensitive data, posing a significant security risk to users leveraging this container storage solution.

Affected Version(s)

overlaybd 0 <= 1.0.18

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.