Debian Package Tracker
Register | Log in
Subscribe

containerd

open and reliable container runtime

Choose email to subscribe with

general
  • source: containerd (main)
  • version: 2.1.9+ds1-5
  • maintainer: Debian Go Packaging Team (DMD)
  • uploaders: Reinhard Tartler [DMD] – Tianon Gravi [DMD] – Tim Potter [DMD] – Shengjing Zhu [DMD]
  • arch: all
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 1.4.13~ds1-1~deb11u4
  • o-o-sec: 1.4.13~ds1-1~deb11u6
  • oldstable: 1.6.20~ds1-1+deb12u3
  • old-sec: 1.6.20~ds1-1+deb12u2
  • stable: 1.7.24~ds1-6+deb13u1
  • stable-sec: 1.7.24~ds1-6+deb13u1
  • testing: 2.1.9+ds1-3
  • unstable: 2.1.9+ds1-5
versioned links
  • 1.4.13~ds1-1~deb11u4: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.4.13~ds1-1~deb11u6: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.6.20~ds1-1+deb12u2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.6.20~ds1-1+deb12u3: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.7.24~ds1-6+deb13u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.1.9+ds1-3: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.1.9+ds1-5: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • containerd (1 bugs: 0, 1, 0, 0)
  • golang-github-containerd-containerd-api-dev
  • golang-github-containerd-containerd-dev
action needed
Marked for autoremoval on 21 October due to golang-github-frankban-quicktest, golang-pgregory-rapid: #1146192, #1146223 high
Version 2.1.9+ds1-3 of containerd is marked for autoremoval from testing on Wed 21 Oct 2026. It depends (transitively) on golang-github-frankban-quicktest, golang-pgregory-rapid, affected by #1146192, #1146223. You should try to prevent the removal by fixing these RC bugs.
Created: 2026-09-04 Last update: 2026-10-05 03:20
A new upstream version is available: 2.4.1 high
A new upstream version 2.4.1 is available, you should consider packaging it.
Created: 2026-10-05 Last update: 2026-10-05 01:00
5 security issues in trixie high

There are 5 open security issues in trixie.

5 important issues:
  • CVE-2026-46680: containerd is an open-source container runtime. In versions prior to 1.7.32, 2.0.9, 2.2.4 and 2.3.1, containers launched with a numeric User directive that cannot be parsed as a 32-bit integer are incorrectly treated as a username, leading to runAsNonRoot evasion. If a crafted image provides an /etc/passwd file mapping this large numeric string to root, the container ultimately runs as root (UID 0). This allows the Kubernetes runAsNonRoot restriction to be bypassed, causing unexpected behavior for environments that require containers to run as a non-root user. This issue has been fixed in versions 1.7.32, 2.0.9, 2.2.4 and 2.3.1.
  • CVE-2026-47262: containerd is an open-source container runtime. Versions prior to 1.7.33, 2.0.10, 2.1.9, 2.2.5 and 2.3.2, contain a vulnerability that allows a maliciously crafted image to cause a Denial of Service (DoS) condition. When creating a container from this image, memory exhaustion occurs, leading to an Out Of Memory (OOM) kill of the containerd process. This renders the container runtime API unavailable and can disrupt clients such as the Docker Engine or Kubernetes control-plane components. This issue has been fixed in versions 1.7.33, 2.0.10, 2.1.9, 2.2.5 and 2.3.2.
  • CVE-2026-53488: containerd is an open-source container runtime. In versions prior to 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10 the CRI plugin propagates labels from an image config (LABEL instruction in Dockerfile) to a container without validation. This may result in executing an arbitrary command on the host, via a plugin that consumes container labels for some operations. This issue has been fixed in versions 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10.
  • CVE-2026-53493: containerd is an open-source container runtime. Prior to versions 1.7.36, 2.0.13, 2.2.9, 2.3.6, and 2.4.1, a crafted OCI index graph can force very high CPU/memory usage during PullImage (before container start), causing long ContainerCreating stalls and, at larger sizes, node/runtime instability. Versions 1.7.36, 2.0.13, 2.2.9, 2.3.6, and 2.4.1 fix the issue.
  • CVE-2026-53495: containerd is an open-source container runtime. Prior to 1.7.35, 2.0.12, 2.2.8, and 2.3.5, containerd on Linux with the CRI plugin enabled can indefinitely block the drainExecSyncIO goroutine in internal/cri/server/container_execsync.go when CRI ExecSync is used by exec probes or lifecycle hooks that launch long-lived background child processes retaining standard input and output pipes. The input and output drain phase has no default timeout and did not stop when the request context was canceled, so repeated ExecSync invocations can accumulate blocked goroutines and host memory. The resulting resource exhaustion can cause the OOM killer to terminate containerd, leaving the container runtime unavailable until restart. Deployments not using containerd's CRI implementation and containers not running on Linux are not affected. This issue is fixed in versions 1.7.35, 2.0.12, 2.2.8, and 2.3.5.
Created: 2026-06-19 Last update: 2026-10-04 22:00
1 security issue in sid high

There is 1 open security issue in sid.

1 important issue:
  • CVE-2026-53493: containerd is an open-source container runtime. Prior to versions 1.7.36, 2.0.13, 2.2.9, 2.3.6, and 2.4.1, a crafted OCI index graph can force very high CPU/memory usage during PullImage (before container start), causing long ContainerCreating stalls and, at larger sizes, node/runtime instability. Versions 1.7.36, 2.0.13, 2.2.9, 2.3.6, and 2.4.1 fix the issue.
Created: 2026-07-02 Last update: 2026-10-04 22:00
2 security issues in forky high

There are 2 open security issues in forky.

2 important issues:
  • CVE-2026-53493: containerd is an open-source container runtime. Prior to versions 1.7.36, 2.0.13, 2.2.9, 2.3.6, and 2.4.1, a crafted OCI index graph can force very high CPU/memory usage during PullImage (before container start), causing long ContainerCreating stalls and, at larger sizes, node/runtime instability. Versions 1.7.36, 2.0.13, 2.2.9, 2.3.6, and 2.4.1 fix the issue.
  • CVE-2026-53495: containerd is an open-source container runtime. Prior to 1.7.35, 2.0.12, 2.2.8, and 2.3.5, containerd on Linux with the CRI plugin enabled can indefinitely block the drainExecSyncIO goroutine in internal/cri/server/container_execsync.go when CRI ExecSync is used by exec probes or lifecycle hooks that launch long-lived background child processes retaining standard input and output pipes. The input and output drain phase has no default timeout and did not stop when the request context was canceled, so repeated ExecSync invocations can accumulate blocked goroutines and host memory. The resulting resource exhaustion can cause the OOM killer to terminate containerd, leaving the container runtime unavailable until restart. Deployments not using containerd's CRI implementation and containers not running on Linux are not affected. This issue is fixed in versions 1.7.35, 2.0.12, 2.2.8, and 2.3.5.
Created: 2026-07-02 Last update: 2026-10-04 22:00
5 security issues in bookworm high

There are 5 open security issues in bookworm.

5 important issues:
  • CVE-2026-46680: containerd is an open-source container runtime. In versions prior to 1.7.32, 2.0.9, 2.2.4 and 2.3.1, containers launched with a numeric User directive that cannot be parsed as a 32-bit integer are incorrectly treated as a username, leading to runAsNonRoot evasion. If a crafted image provides an /etc/passwd file mapping this large numeric string to root, the container ultimately runs as root (UID 0). This allows the Kubernetes runAsNonRoot restriction to be bypassed, causing unexpected behavior for environments that require containers to run as a non-root user. This issue has been fixed in versions 1.7.32, 2.0.9, 2.2.4 and 2.3.1.
  • CVE-2026-47262: containerd is an open-source container runtime. Versions prior to 1.7.33, 2.0.10, 2.1.9, 2.2.5 and 2.3.2, contain a vulnerability that allows a maliciously crafted image to cause a Denial of Service (DoS) condition. When creating a container from this image, memory exhaustion occurs, leading to an Out Of Memory (OOM) kill of the containerd process. This renders the container runtime API unavailable and can disrupt clients such as the Docker Engine or Kubernetes control-plane components. This issue has been fixed in versions 1.7.33, 2.0.10, 2.1.9, 2.2.5 and 2.3.2.
  • CVE-2026-53488: containerd is an open-source container runtime. In versions prior to 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10 the CRI plugin propagates labels from an image config (LABEL instruction in Dockerfile) to a container without validation. This may result in executing an arbitrary command on the host, via a plugin that consumes container labels for some operations. This issue has been fixed in versions 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10.
  • CVE-2026-53493: containerd is an open-source container runtime. Prior to versions 1.7.36, 2.0.13, 2.2.9, 2.3.6, and 2.4.1, a crafted OCI index graph can force very high CPU/memory usage during PullImage (before container start), causing long ContainerCreating stalls and, at larger sizes, node/runtime instability. Versions 1.7.36, 2.0.13, 2.2.9, 2.3.6, and 2.4.1 fix the issue.
  • CVE-2026-53495: containerd is an open-source container runtime. Prior to 1.7.35, 2.0.12, 2.2.8, and 2.3.5, containerd on Linux with the CRI plugin enabled can indefinitely block the drainExecSyncIO goroutine in internal/cri/server/container_execsync.go when CRI ExecSync is used by exec probes or lifecycle hooks that launch long-lived background child processes retaining standard input and output pipes. The input and output drain phase has no default timeout and did not stop when the request context was canceled, so repeated ExecSync invocations can accumulate blocked goroutines and host memory. The resulting resource exhaustion can cause the OOM killer to terminate containerd, leaving the container runtime unavailable until restart. Deployments not using containerd's CRI implementation and containers not running on Linux are not affected. This issue is fixed in versions 1.7.35, 2.0.12, 2.2.8, and 2.3.5.
Created: 2026-06-19 Last update: 2026-10-04 22:00
3 security issues in bullseye high

There are 3 open security issues in bullseye.

3 important issues:
  • CVE-2026-46680: containerd is an open-source container runtime. In versions prior to 1.7.32, 2.0.9, 2.2.4 and 2.3.1, containers launched with a numeric User directive that cannot be parsed as a 32-bit integer are incorrectly treated as a username, leading to runAsNonRoot evasion. If a crafted image provides an /etc/passwd file mapping this large numeric string to root, the container ultimately runs as root (UID 0). This allows the Kubernetes runAsNonRoot restriction to be bypassed, causing unexpected behavior for environments that require containers to run as a non-root user. This issue has been fixed in versions 1.7.32, 2.0.9, 2.2.4 and 2.3.1.
  • CVE-2026-47262: containerd is an open-source container runtime. Versions prior to 1.7.33, 2.0.10, 2.1.9, 2.2.5 and 2.3.2, contain a vulnerability that allows a maliciously crafted image to cause a Denial of Service (DoS) condition. When creating a container from this image, memory exhaustion occurs, leading to an Out Of Memory (OOM) kill of the containerd process. This renders the container runtime API unavailable and can disrupt clients such as the Docker Engine or Kubernetes control-plane components. This issue has been fixed in versions 1.7.33, 2.0.10, 2.1.9, 2.2.5 and 2.3.2.
  • CVE-2026-53488: containerd is an open-source container runtime. In versions prior to 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10 the CRI plugin propagates labels from an image config (LABEL instruction in Dockerfile) to a container without validation. This may result in executing an arbitrary command on the host, via a plugin that consumes container labels for some operations. This issue has been fixed in versions 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10.
Created: 2026-06-19 Last update: 2026-09-01 01:32
Multiarch hinter reports 1 issue(s) normal
There are issues with the multiarch metadata for this package.
  • golang-github-containerd-containerd-api-dev could be marked Multi-Arch: foreign
Created: 2025-08-16 Last update: 2026-10-05 02:30
Fails to build during reproducibility testing normal
A package building reproducibly enables third parties to verify that the source matches the distributed binaries. It has been identified that this source package produced different results, failed to build or had other issues in a test environment. Please read about how to improve the situation!
Created: 2026-06-23 Last update: 2026-10-05 02:00
1 open merge request in Salsa normal
There is 1 open merge request for this package on Salsa. You should consider reviewing and/or merging these merge requests.
Created: 2026-09-28 Last update: 2026-09-28 23:00
lintian reports 3 warnings normal
Lintian reports 3 warnings about this package. You should make the package lintian clean getting rid of them.
Created: 2026-04-03 Last update: 2026-09-13 20:32
debian/patches: 1 patch to forward upstream low

Among the 8 debian patches available in version 2.1.9+ds1-4 of the package, we noticed the following issues:

  • 1 patch where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2026-10-04 Last update: 2026-10-04 09:30
testing migrations
  • excuses:
    • Migration status for containerd (2.1.9+ds1-3 to 2.1.9+ds1-4): BLOCKED: Maybe temporary, maybe blocked but Britney is missing information (check below)
    • Issues preventing migration:
    • ∙ ∙ Missing build on riscv64
    • ∙ ∙ Not built on buildd: upload info for arch amd64 binaries not found
    • ∙ ∙ Not built on buildd: upload info for arch all binaries not found, a new source-only upload is needed to allow migration
    • ∙ ∙ Not built on buildd: upload info for arch arm64 binaries not found
    • ∙ ∙ Not built on buildd: upload info for arch armhf binaries not found
    • ∙ ∙ Not built on buildd: upload info for arch i386 binaries not found
    • ∙ ∙ Not built on buildd: upload info for arch loong64 binaries not found
    • ∙ ∙ Not built on buildd: upload info for arch ppc64el binaries not found
    • ∙ ∙ Not built on buildd: upload info for arch s390x binaries not found
    • ∙ ∙ Autopkgtest deferred on riscv64: missing arch:riscv64 build
    • ∙ ∙ Autopkgtest for containerd/2.1.9+ds1-4: amd64: Pass, arm64: Failed (not a regression) ♻ (reference ♻), armhf: Failed (not a regression) ♻ (reference ♻), i386: Failed (not a regression) ♻ (reference ♻), ppc64el: Failed (not a regression) ♻ (reference ♻), s390x: Failed (not a regression) ♻ (reference ♻)
    • ∙ ∙ Lintian check waiting for test results on riscv64 - info
    • ∙ ∙ Too young, only 1 of 5 days old
    • Additional info (not blocking):
    • ∙ ∙ Piuparts tested OK - https://piuparts.debian.org/sid/source/c/containerd.html
    • ∙ ∙ Reproduced on amd64 - info
    • ∙ ∙ Reproduced on arm64 - info
    • ∙ ∙ Reproduced on armhf - info
    • ∙ ∙ Reproduced on i386 - info
    • Not considered
news
[rss feed]
  • [2026-10-04] Accepted containerd 2.1.9+ds1-5 (source) into unstable (Reinhard Tartler)
  • [2026-10-03] Accepted containerd 2.1.9+ds1-4 (source) into unstable (Reinhard Tartler)
  • [2026-09-22] containerd 2.1.9+ds1-3 MIGRATED to testing (Debian testing watch)
  • [2026-09-16] Accepted containerd 2.1.9+ds1-3 (source) into unstable (Reinhard Tartler)
  • [2026-09-06] containerd 2.1.9+ds1-2 MIGRATED to testing (Debian testing watch)
  • [2026-08-31] Accepted containerd 2.1.9+ds1-2 (source) into unstable (Reinhard Tartler)
  • [2026-06-22] containerd 2.1.9+ds1-1 MIGRATED to testing (Debian testing watch)
  • [2026-06-19] Accepted containerd 2.1.9+ds1-1 (source) into unstable (Reinhard Tartler)
  • [2026-04-06] Accepted containerd 1.6.20~ds1-1+deb12u3 (source) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Arnaud Rebillout)
  • [2026-04-05] containerd 2.1.6+ds1-1 MIGRATED to testing (Debian testing watch)
  • [2026-04-02] Accepted containerd 2.1.6+ds1-1 (source) into unstable (Reinhard Tartler)
  • [2026-03-29] containerd 2.1.4~ds2-8 MIGRATED to testing (Debian testing watch)
  • [2026-03-23] Accepted containerd 2.1.4~ds2-8 (source) into unstable (Reinhard Tartler)
  • [2026-03-20] Accepted containerd 2.1.4~ds2-7 (source) into unstable (Reinhard Tartler)
  • [2026-03-20] Accepted containerd 2.1.4~ds2-6 (source) into experimental (Reinhard Tartler)
  • [2026-02-05] Accepted containerd 1.4.13~ds1-1~deb11u6 (source) into oldoldstable-security (Arnaud Rebillout)
  • [2026-01-11] Accepted containerd 2.1.4~ds2-5 (source) into experimental (Reinhard Tartler)
  • [2026-01-10] Accepted containerd 2.1.4~ds2-4 (source) into experimental (Reinhard Tartler)
  • [2026-01-03] Accepted containerd 2.1.4~ds2-3 (source) into experimental (Reinhard Tartler)
  • [2026-01-02] Accepted containerd 2.1.4~ds2-2 (source) into experimental (Reinhard Tartler)
  • [2025-12-06] Accepted containerd 1.7.24~ds1-6+deb13u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Reinhard Tartler)
  • [2025-12-05] Accepted containerd 1.6.20~ds1-1+deb12u2 (source) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Reinhard Tartler)
  • [2025-12-02] Accepted containerd 1.7.24~ds1-6+deb13u1 (source) into stable-security (Debian FTP Masters) (signed by: Reinhard Tartler)
  • [2025-12-02] Accepted containerd 1.6.20~ds1-1+deb12u2 (source) into oldstable-security (Debian FTP Masters) (signed by: Reinhard Tartler)
  • [2025-11-10] containerd 1.7.24~ds1-10 MIGRATED to testing (Debian testing watch)
  • [2025-11-08] Accepted containerd 1.7.24~ds1-10 (source) into unstable (Reinhard Tartler)
  • [2025-11-07] Accepted containerd 1.7.24~ds1-9 (source) into unstable (Reinhard Tartler)
  • [2025-08-20] containerd 1.7.24~ds1-8 MIGRATED to testing (Debian testing watch)
  • [2025-08-15] Accepted containerd 1.7.24~ds1-8 (source) into unstable (Reinhard Tartler)
  • [2025-08-14] Accepted containerd 1.7.24~ds1-7 (all amd64 source) into experimental (Debian FTP Masters) (signed by: Reinhard Tartler)
  • 1
  • 2
bugs [bug history graph]
  • all: 1
  • RC: 0
  • I&N: 1
  • M&W: 0
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian (0, 3)
  • buildd: logs, reproducibility
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 2.1.9+ds1-3ubuntu1
  • 2 bugs
  • patches for 2.1.9+ds1-3ubuntu1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing