Critical containerd CRI Plugin Vulnerabilities Affect AWS Container Services
Five security flaws discovered in containerd versions 1.7–2.3 impact AWS EKS, ECS, Fargate, and Bottlerocket. Issues range from local image poisoning and arbitrary file reads to command execution and DoS attacks. If you're running these services, patch immediately—this one's serious and requires your attention.
source: [aws/security-bulletin]