GHSA-6g2q-w5j3-fwh4 · Severity: medium · Ecosystem: go — containerd environment variable leak
In containerd (an industry-standard container runtime) before versions 1.3.10 and 1.4.4, containers launched through containerd's CRI implementation (through Kubernetes, crictl, or any other pod/container client that uses the containerd CRI service) that share the same image may receive incorrect environment variables, including values that are defined for other containers. If the affected containers have different security contexts, this may allow sensitive information to be unintentionally shared. If you are not using containerd's CRI implementation (through one of the mechanisms described above), you are not vulnerable to this issue. If you are not launching multiple containers or Kubernetes pods from the same image which have different environment variables, you are not vulnerable to this issue. If you are not launching multiple containers or Kubernetes pods from the same image in rapid succession, you have reduced likelihood of being vulnerable to this issue This vulnerability has been fixed in containerd 1.3.10 and containerd 1.4.4. Users should update to these versions.
Conclusion & alert: CVE-2021-21334 is rated Moderate Risk (54.3/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 2.04%). Core evidence: EPSS rose +1.64% over the last day, indicating growing attacker interest. Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.40% | 2.04% | +1.64% |
| 2 | 2026-06-01 | 0.47% | 0.40% | -0.07% |
| 3 | 2026-02-26 | — | 0.47% | — |
Full EPSS history (18 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 6.3 | 3.1 | MEDIUM |
|
1.8 | 4.0 | [email protected] |
| 6.3 | 3.1 | MEDIUM |
|
1.8 | 4.0 | [email protected] |
| 4.3 | 2.0 | MEDIUM |
|
8.6 | 2.9 | [email protected] |
GHSA-6g2q-w5j3-fwh4 · Severity: medium · Ecosystem: go — containerd environment variable leak
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
medium | CVE-2021-21334: 2 source package rows (containerd, k3s); 26 state rows across 7 repos (3.17-community, 3.18-community, 3.19-community, 3.20-community, 3.21-community, 3.22-community, edge-community); fixed 14, open 12. | https://security.alpinelinux.org/vuln/CVE-2021-21334 |
debian
|
not yet assigned | CVE-2021-21334 not yet assigned priority: Debian including 1 source packages (containerd), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2021-21334 |
gentoo
|
high | CVE-2021-21334: 1 GLSA(s) (202105-33), 1 atom(s) (app-emulation/containerd); latest impact high. | https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2021-21334 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2021-21334 |
suse
|
medium | CVE-2021-21334 severity moderate: SUSE including 273 source package names (2.0.2-4.2.20:runc-1.0.0~rc93-1.14.2, amazon/suse-sles-15-sp1-chost-byos-v20210304-hvm-ssd-x86_64, …), 1251 product×package rows across 326 product lines (Container rancher/elemental-teal-iso/5.4, Container rancher/elemental-teal-rt/5.4, … (326 product lines)): Fixed 1062, Known Affected 136, Known Not Affected 53. | https://www.suse.com/security/cve/CVE-2021-21334/ |
ubuntu
|
medium | CVE-2021-21334 medium priority: Ubuntu including 1 source packages (containerd), 16 status rows across 16 suites (bionic, focal, groovy, hirsute, impish, jammy, kinetic, lunar, mantic, noble, oracular, plucky, questing, trusty, upstream, xenial): released 14, DNE 1, needed 1. | https://ubuntu.com/security/CVE-2021-21334 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| linuxfoundation | containerd | < 1.3.10 | cpe:2.3:a:linuxfoundation:containerd:*:*:*:*:*:*:*:* |
| linuxfoundation | containerd | >= 1.4.0, < 1.4.4 | cpe:2.3:a:linuxfoundation:containerd:*:*:*:*:*:*:*:* |
| fedoraproject | fedora | 33 | cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:* |
| fedoraproject | fedora | 34 | cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:* |