Overview :
Access controls vulnerabilities in containerd containers
Affected Product(s) :
Vulnerability Details :
CVE ID :CVE-2020-15257
CVE-2020–15257 disclosed on November 30, 2020 is an attack vector that allowed containerd containers running in the host network namespace with UID 0 to gain the host root privileges, via containerd’s abstract sockets exposed in the host network namespace.

Solution :

The CVE was fixed in containerd v1.4.3/v1.3.9, by switching away from abstract sockets into plain old file-based UNIX sockets under