Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2021-43816

29
FAUCET Score

CVE-2021-43816 is a critical vulnerability affecting containerd, an open-source container runtime, specifically on SELinux-enabled systems like EL8 and Fedora, when used as a Container Runtime Interface (CRI). An unprivileged pod can achieve full read/write access to privileged host files by binding them to specific container locations (/etc/hosts, /etc/hostname, or /etc/resolv.conf), due to indiscriminate SELinux relabeling. This vulnerability carries a CVSS score of 9.1 (CRITICAL) due to its network attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.5.1, < 1.5.9CPE matchmatch criteria
cpe:2.3:a:linuxfoundation:containerd:*:*:*:*:*:*:*:*
1.5.0CPE matchmatch criteria
cpe:2.3:a:linuxfoundation:containerd:1.5.0:-:*:*:*:*:*:*
1.5.0CPE matchmatch criteria
cpe:2.3:a:linuxfoundation:containerd:1.5.0:beta0:*:*:*:*:*:*
1.5.0CPE matchmatch criteria
cpe:2.3:a:linuxfoundation:containerd:1.5.0:beta1:*:*:*:*:*:*
1.5.0CPE matchmatch criteria
cpe:2.3:a:linuxfoundation:containerd:1.5.0:beta2:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.0HIGH

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
HIGH
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.3
Impact Score
6.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.69%
Probability of exploitation in next 30 days
EPSS Percentile
74.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
This CVE's current EPSS score of 0.0169 is in the 70th percentile among its peer group of 460 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.7 Bluesky, 0.4 Mastodon, and 1.7 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (12)

github_advisorypatch availablevia nvd_reference
View patch
gopatch availablevia ghsa
Product: github.com/containerd/containerdFixed in: 1.5.9
redhatno patchvia redhat_api
Product: Red Hat Advanced Cluster Management for Kubernetes 2Fixed in: multicloud-operators-channel-container
redhatno patchvia redhat_api
Product: Red Hat Advanced Cluster Management for Kubernetes 2Fixed in: multicloud-operators-subscription-container
redhatno patchvia redhat_api
Product: Red Hat Advanced Cluster Management for Kubernetes 2Fixed in: multicloud-operators-subscription-release-container
redhatno patchvia redhat_api
Product: Red Hat Advanced Cluster Management for Kubernetes 2Fixed in: multicluster-hub-repo-container
redhatno patchvia redhat_api
Product: Red Hat Advanced Cluster Management for Kubernetes 2Fixed in: rhacm2/prometheus-rhel8
redhatno patchvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openshift
redhatend of lifevia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openshift-clients
redhatend of lifevia redhat_api
Product: Red Hat OpenStack Platform 16.2Fixed in: osp-director-provisioner-container
redhatend of lifevia redhat_api
Product: Red Hat OpenStack Platform 16.2Fixed in: rhosp-rhel8/osp-director-downloader
redhatend of lifevia redhat_api
Product: Red Hat OpenStack Platform 16.2Fixed in: rhosp-rhel8/osp-director-operator

Vendor Advisories (2)

goGHSA-mvff-h3cj-wj9chigh

Unprivileged pod using `hostPath` can side-step active LSM when it is SELinux

Jan 6, 2022
redhatCVE-2021-43816Important

containerd: Unprivileged pod may bind mount any privileged regular file on disk

Jan 5, 2022

References

github.com / containerd/containerd/commit/a731039238c62be081eb8c31525b988415745eea
PatchThird Party Advisory
github.com / containerd/containerd/issues/6194
ExploitIssue TrackingThird Party Advisory
github.com / containerd/containerd/security/advisories/GHSA-mvff-h3cj-wj9c
Third Party Advisory
github.com / dweomer/containerd/commit/f7f08f0e34fb97392b0d382e58916d6865100299
PatchThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/GD5GH7NMK5VJMA2Y5CYB5O5GTPYMWMLX
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/MPDIZMI7ZPERSZE2XO265UCK5IWM7CID