Package
kargo-1.11
Component
github.com/containerd/containerd
Latest update
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Justification
Impact
The affected-component scope in this advisory is the containerd/containerd/v2 Go module (CRI checkpoint/restore functionality added in the 2.x line); the vulnerable version range is 2.1.0-2.3.2. The package pins the separate, legacy containerd/containerd v1 module, which does not appear in the affected range, and the v2 module is absent from the dependency graph entirely. Upstream containerd maintainers have confirmed directly that the vulnerable code is not present in the 1.7 line. The raw Go vulnerability database also lists the bare v1 module as affected with no fixed version; this is a known, unresolved cataloging discrepancy (golang/vulndb#5780) not reflected in the GHSA's own human-reviewed scoping.
Status