CVE-2025-64329: containerd CRI server: Host memory exhaustion through Attach goroutine leak
(updated )
A bug was found in containerd’s CRI Attach implementation where a user can exhaust memory on the host due to goroutine leaks.
Repetitive calls of CRI Attach (e.g., kubectl attach) could increase the memory usage of containerd.
References
Code Behaviors & Features
Detect and mitigate CVE-2025-64329 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →