CVE-2026-107446: Containerd Overlaybd

Medium severity, CVSS 6.8. EPSS: 0.4% chance of exploitation in the next 30 days.

containerd overlaybd through 1.0.18 has a do_load_index (LSMT index loading) integer overflow (and resultant out-of-bounds heap access) for index_bytes, if an untrusted overlaybd blob from a registry is used in a scenario with multiple overlaybd-backed containers.

Affected products

Published 2026-10-08. Last modified 2026-10-08.