OverlayBD LSMT index size integer overflow causes out-of-bounds heap access
Fixed in: Public code fix merged; fixed release not independently confirmed
details
- Finding IDs
- F-OVERLAYBD-001-002
- CVE
- CVE-2026-107446
- Status
- fixed in public code; release unconfirmed
- Fixed in
- Public code fix merged; fixed release not independently confirmed
- Reported date
- Note
- CVE published on 8 October 2026 for containerd overlaybd through 1.0.18: integer overflow in do_load_index when loading LSMT index metadata can cause out-of-bounds heap access when an untrusted registry blob is used with multiple overlaybd-backed containers. This is the existing researcher report F-OVERLAYBD-001-002, not an additional finding. The CVE references public index-size validation PR #438, merged on 18 August 2026. A fixed release has not been independently confirmed. The public CVE record does not include a reporter credit; the report mapping is researcher-confirmed, and the vendor patch is not attributed to 1seal.
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H
- CVE registry state
- PUBLISHED
- CVE state checked
- CVSS assessment
- MITRE CVE record; v3.1; 6.8; observed 2026-10-08
F-OVERLAYBD-001-002: Memory safety. Untrusted LSMT index metadata can overflow index_bytes and cause out-of-bounds heap access. Reviewed 8 Oct 2026. Mechanism assessed by 1seal.
Mechanism source for F-OVERLAYBD-001-002
Security area (1seal assessment): Memory safety. Untrusted LSMT index metadata can overflow index_bytes and cause out-of-bounds heap access. Reviewed 8 Oct 2026.