THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-7jxh-36q5-gcqv (medium) — containerd: CRI ExecSync Goroutine Leak Leads to Node-Level Denial of Service

[GHSA] GHSA-7jxh-36q5-gcqv (medium) — containerd: CRI ExecSync Goroutine Leak Leads to Node-Level Denial of Service

medgithub_advisoriesPublished 2026-09-09

GHSA-7jxh-36q5-gcqv Severity: medium CVE: CVE-2026-53495

containerd: CRI ExecSync Goroutine Leak Leads to Node-Level Denial of Service

### Impact

A bug in containerd's CRI ExecSync implementation allows exec probes and lifecycle hooks with background child processes to keep containerd's stdio-drain goroutines indefinitely blocked. Because the I/O drain phase lacks a default timeout or context c

Indicators of compromise

Original source: https://github.com/advisories/GHSA-7jxh-36q5-gcqv