In plain language
What this advisory means
Amazon Web Services (AWS) identified five security vulnerabilities in the containerd CRI plugin, a key component used in AWS managed container services and Kubernetes environments. These vulnerabilities could allow attackers to execute code, read host files, inject devices, cause denial of service, or execute arbitrary commands on affected systems if exploited. AWS has released patches for these issues and is updating its managed services to protect customers.
Technical explanation
How the issue affects the environment
The containerd CRI plugin versions 1.7 through 2.3 contain five distinct vulnerabilities: CVE-2026-50195 allows image cache poisoning leading to cross-pod code execution via unvalidated checkpoint image references. CVE-2026-53488 enables arbitrary host command execution through unsanitized image LABEL instructions. CVE-2026-53492 trusts CDI annotations from unvalidated checkpoint metadata, allowing device and host mount injection, bypassing Kubernetes device enforcement, if CDI is enabled. CVE-2026-53489 fails to validate symlinked container log paths during checkpoint restore, enabling arbitrary host file reads. CVE-2026-47262 causes uncontrolled memory consumption via crafted container images, leading to out-of-memory termination and denial of service of containerd and all containers on the node. AWS is deploying patched containerd runtimes in managed services and recommends users of self-managed containerd upgrade promptly.
Operational impact
Why teams should care
These vulnerabilities can lead to cross-pod code execution, arbitrary command execution on the host, unauthorized access to host files, injection of unauthorized devices, and denial of service. This compromises container isolation and system stability, potentially impacting the security of applications running on AWS managed container services or self-managed containerd deployments. Failure to remediate could lead to unauthorized access, data breaches, service disruption, and increased operational risks.
Immediate action
AWS recommends upgrading to the latest patched containerd version available from the upstream containerd project. AWS is deploying patched runtimes to managed container services such as Amazon EKS, ECS, and Fargate. For self-managed containerd deployments, upgrade to patched versions immediately. Additionally, verify any forked or derivative containerd code is updated to include these fixes.
Affected and fixed releases
Temporary risk reduction
For CVE-2026-47262, only allow trusted container images to be pulled and restrict image import and pod scheduling to trusted users. For CVE-2026-50195 and CVE-2026-53488, restrict image pulls to trusted sources. For CVE-2026-53489, only restore containers from trusted checkpoints and use trusted images. For CVE-2026-53492, allow restoration from trusted checkpoint images only and, if CDI is unused, temporarily remove or relocate host CDI specifications from /etc/cdi and /var/run/cdi directories to block exploitation.
Evidence and validation checklist
- Vendor advisory from AWS Security Bulletins dated June 18, 2026, last updated June 22, 2026.
- Descriptions of each CVE and their technical impact with CVSS scores.
- Mention that AWS is deploying patched runtimes across managed services.
- Recommendations for upgrading self-managed containerd deployments.
- Workarounds issued per CVE.
- References to containerd upstream security advisories.
Authoritative reference
AWS Security Bulletins
QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.
