1sealsemantic last-mile verification

Research / Finding

OverlayBD LSMT index size integer overflow causes out-of-bounds heap access

F-OVERLAYBD-001-002

Public snapshot: 8 Oct 2026. Status, releases and attribution belong to each source below; none is inferred from another record.

Read the evidence · View in research browse

Recorded evidence

6.8medium
CVE-2026-107446CVEcontainerd/overlaybd

OverlayBD LSMT index size integer overflow causes out-of-bounds heap access

Fixed in: Public code fix merged; fixed release not independently confirmed

fixed in public code; release unconfirmed
details
Finding IDs
F-OVERLAYBD-001-002
CVE
CVE-2026-107446
Status
fixed in public code; release unconfirmed
Fixed in
Public code fix merged; fixed release not independently confirmed
Reported date
Note
CVE published on 8 October 2026 for containerd overlaybd through 1.0.18: integer overflow in do_load_index when loading LSMT index metadata can cause out-of-bounds heap access when an untrusted registry blob is used with multiple overlaybd-backed containers. This is the existing researcher report F-OVERLAYBD-001-002, not an additional finding. The CVE references public index-size validation PR #438, merged on 18 August 2026. A fixed release has not been independently confirmed. The public CVE record does not include a reporter credit; the report mapping is researcher-confirmed, and the vendor patch is not attributed to 1seal.
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H
CVE registry state
PUBLISHED
CVE state checked
CVSS assessment
MITRE CVE record; v3.1; 6.8; observed 2026-10-08

F-OVERLAYBD-001-002: Memory safety. Untrusted LSMT index metadata can overflow index_bytes and cause out-of-bounds heap access. Reviewed 8 Oct 2026. Mechanism assessed by 1seal.

Mechanism source for F-OVERLAYBD-001-002

Security area (1seal assessment): Memory safety. Untrusted LSMT index metadata can overflow index_bytes and cause out-of-bounds heap access. Reviewed 8 Oct 2026.

Clarify or correct this record privately. The email subject includes the finding ID. For an existing case, continue the agreed private thread. Do not post unpublished vulnerability details in public issues. Research disclosure policy.

How this page groups evidence

This identifier groups recorded evidence; it is not an additional CVE, independent-vulnerability count or guarantee of vendor confirmation. Fixed code, released versions, attribution and independent discovery are distinct claims. Absent metadata means not recorded, not disproved. Counting rules.