GHSA-mvff-h3cj-wj9c · Severity: high · Ecosystem: go — Unprivileged pod using `hostPath` can side-step active LSM when it is SELinux
containerd is an open source container runtime. On installations using SELinux, such as EL8 (CentOS, RHEL), Fedora, or SUSE MicroOS, with containerd since v1.5.0-beta.0 as the backing container runtime interface (CRI), an unprivileged pod scheduled to the node may bind mount, via hostPath volume, any privileged, regular file on disk for complete read/write access (sans delete). Such is achieved by placing the in-container location of the hostPath volume mount at either `/etc/hosts`, `/etc/hostname`, or `/etc/resolv.conf`. These locations are being relabeled indiscriminately to match the container process-label which effectively elevates permissions for savvy containers that would not normally be able to access privileged host files. This issue has been resolved in version 1.5.9. Users are advised to upgrade as soon as possible.
Conclusion & alert: CVE-2021-43816 is rated High Exploit Risk (74.4/100): CVSS High severity, with medium exploitation likelihood (EPSS 1.69%). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). EPSS rose +1.54% over the last day, indicating growing attacker interest. Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.15% | 1.69% | +1.54% |
| 2 | 2025-11-21 | 0.67% | 0.15% | -0.52% |
| 3 | 2025-11-18 | — | 0.67% | — |
Full EPSS history (16 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.0 | 3.1 | HIGH |
|
1.3 | 6.0 | [email protected] |
| 9.1 | 3.1 | CRITICAL |
|
2.3 | 6.0 | [email protected] |
| 6.0 | 2.0 | MEDIUM |
|
6.8 | 6.4 | [email protected] |
GHSA-mvff-h3cj-wj9c · Severity: high · Ecosystem: go — Unprivileged pod using `hostPath` can side-step active LSM when it is SELinux
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
critical | CVE-2021-43816: 1 source package rows (containerd); 13 state rows across 7 repos (3.17-community, 3.18-community, 3.19-community, 3.20-community, 3.21-community, 3.22-community, edge-community); fixed 7, open 6. | https://security.alpinelinux.org/vuln/CVE-2021-43816 |
debian
|
unimportant | CVE-2021-43816 unimportant priority: Debian including 1 source packages (containerd), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2021-43816 |
redhat
|
high | — | https://access.redhat.com/security/cve/CVE-2021-43816 |
suse
|
high | CVE-2021-43816 severity important: SUSE including 2 source package names (containerd, containerd-ctr), 39 product×package rows across 26 product lines (SUSE CaaS Platform 4.0, SUSE CaaS Platform 4.5, … (26 product lines)): Known Not Affected 39. | https://www.suse.com/security/cve/CVE-2021-43816/ |
ubuntu
|
low | CVE-2021-43816 low priority: Ubuntu including 1 source packages (containerd), 15 status rows across 15 suites (bionic, focal, hirsute, impish, jammy, kinetic, lunar, mantic, noble, oracular, plucky, questing, trusty, upstream, xenial): released 12, ignored 2, needed 1. | https://ubuntu.com/security/CVE-2021-43816 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| linuxfoundation | containerd | >= 1.5.1, < 1.5.9 | cpe:2.3:a:linuxfoundation:containerd:*:*:*:*:*:*:*:* |
| linuxfoundation | containerd | 1.5.0 | cpe:2.3:a:linuxfoundation:containerd:1.5.0:-:*:*:*:*:*:* |
| linuxfoundation | containerd | 1.5.0 | cpe:2.3:a:linuxfoundation:containerd:1.5.0:beta0:*:*:*:*:*:* |
| linuxfoundation | containerd | 1.5.0 | cpe:2.3:a:linuxfoundation:containerd:1.5.0:beta1:*:*:*:*:*:* |
| linuxfoundation | containerd | 1.5.0 | cpe:2.3:a:linuxfoundation:containerd:1.5.0:beta2:*:*:*:*:*:* |
| linuxfoundation | containerd | 1.5.0 | cpe:2.3:a:linuxfoundation:containerd:1.5.0:beta3:*:*:*:*:*:* |
| linuxfoundation | containerd | 1.5.0 | cpe:2.3:a:linuxfoundation:containerd:1.5.0:beta4:*:*:*:*:*:* |
| linuxfoundation | containerd | 1.5.0 | cpe:2.3:a:linuxfoundation:containerd:1.5.0:rc0:*:*:*:*:*:* |
| linuxfoundation | containerd | 1.5.0 | cpe:2.3:a:linuxfoundation:containerd:1.5.0:rc1:*:*:*:*:*:* |
| linuxfoundation | containerd | 1.5.0 | cpe:2.3:a:linuxfoundation:containerd:1.5.0:rc2:*:*:*:*:*:* |
| linuxfoundation | containerd | 1.5.0 | cpe:2.3:a:linuxfoundation:containerd:1.5.0:rc3:*:*:*:*:*:* |
| fedoraproject | fedora | 34 | cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:* |
| fedoraproject | fedora | 35 | cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:* |