THREAT OPS › Threat News › [GHSA] GHSA-7jxh-36q5-gcqv (medium) — containerd: CRI ExecSync Goroutine Leak Leads to Node-Level Denial of Service
[GHSA] GHSA-7jxh-36q5-gcqv (medium) — containerd: CRI ExecSync Goroutine Leak Leads to Node-Level Denial of Service
GHSA-7jxh-36q5-gcqv Severity: medium CVE: CVE-2026-53495
containerd: CRI ExecSync Goroutine Leak Leads to Node-Level Denial of Service
### Impact
A bug in containerd's CRI ExecSync implementation allows exec probes and lifecycle hooks with background child processes to keep containerd's stdio-drain goroutines indefinitely blocked. Because the I/O drain phase lacks a default timeout or context c
Indicators of compromise
- CVE-2026-53495cve
- xlabai@tencent.comemail
- security@containerd.ioemail
Original source: https://github.com/advisories/GHSA-7jxh-36q5-gcqv