Debian Package Tracker
Register | Log in
Subscribe

containerd

open and reliable container runtime

Choose email to subscribe with

general
  • source: containerd (main)
  • version: 2.1.9+ds1-2
  • maintainer: Debian Go Packaging Team (DMD)
  • uploaders: Shengjing Zhu [DMD] – Tianon Gravi [DMD] – Tim Potter [DMD] – Reinhard Tartler [DMD]
  • arch: all
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 1.4.13~ds1-1~deb11u4
  • o-o-sec: 1.4.13~ds1-1~deb11u6
  • oldstable: 1.6.20~ds1-1+deb12u3
  • old-sec: 1.6.20~ds1-1+deb12u2
  • stable: 1.7.24~ds1-6+deb13u1
  • stable-sec: 1.7.24~ds1-6+deb13u1
  • testing: 2.1.9+ds1-2
  • unstable: 2.1.9+ds1-2
versioned links
  • 1.4.13~ds1-1~deb11u4: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.4.13~ds1-1~deb11u6: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.6.20~ds1-1+deb12u2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.6.20~ds1-1+deb12u3: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.7.24~ds1-6+deb13u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.1.9+ds1-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • containerd (1 bugs: 0, 1, 0, 0)
  • golang-github-containerd-containerd-api-dev
  • golang-github-containerd-containerd-dev
action needed
Marked for autoremoval on 11 October due to golang-github-containerd-stargz-snapshotter, golang-github-frankban-quicktest, golang-github-go-git-go-git, golang-github-go-logr-logr, golang-github-go-quicktest-qt, golang-github-google-go-github, golang-github-googleapis-gax-go, golang-github-klauspost-compress, golang-github-peterbourgon-diskv, golang-github-prometheus-client-golang, golang-github-rogpeppe-go-internal, golang-k8s-apimachinery, golang-k8s-kube-openapi, golang-pgregory-rapid: #1147127, #1146000, #1146189, #1146192, #1146194, #1146195, #1146197, #1146199, #1146200, #1146203, #1146207, #1146219, #1146220, #1146223, #1146612 high
Version 2.1.9+ds1-2 of containerd is marked for autoremoval from testing on Sun 11 Oct 2026. It is affected by #1147127. The removal of containerd will also cause the removal of (transitive) reverse dependencies: aac-tactics, aflplusplus, apt-transport-oci, atlas-ecmwf, belenios, ben, botch, calendar, camlp5, camlp5-buildscripts, camomile, ceilometer-instance-poller, cockpit-podman, coq, coq-bignums, coq-dpdgraph, coq-equations, coq-ext-lib, coq-gappa, coq-hammer, coq-hott, coq-iris, coq-libhyps, coq-math-classes, coq-menhirlib, coq-mtac2, coq-record-update, coq-reduction-effects, coq-simple-io, coq-stdpp, coq-unicoq, coq-unimath, coqprime, cosign, crowdsec, crowdsec-custom-bouncer, debcraft, distrobox, distrobuilder, dochelp, docker-buildx, docker-clean, docker-compose, docker-credential-gcr, docker.io, dose3, due, ectrans, eliom, elpi, eztrace, eztrace-contrib, flocq, ggml, ggml-cuda, gitsign, gittuf, gloo-rocm, go-containerregistry, golang-github-apptainer-container-library-client, golang-github-apptainer-sif, golang-github-awslabs-soci-snapshotter, golang-github-checkpoint-restore-checkpointctl, golang-github-containerd-accelerated-container-image, golang-github-containerd-imgcrypt, golang-github-containerd-nydus-snapshotter, golang-github-containerd-stargz-snapshotter, golang-github-containers-buildah, golang-github-containers-common, golang-github-containers-image, golang-github-containers-psgo, golang-github-containers-storage, golang-github-containers-toolbox, golang-github-crc-org-crc, golang-github-crowdsecurity-go-cs-bouncer, golang-github-fsouza-go-dockerclient, golang-github-in-toto-archivista, golang-github-in-toto-go-witness, golang-github-openshift-imagebuilder, golang-github-sigstore-fulcio, golang-github-sigstore-rekor-tiles, golang-github-sigstore-sigstore, golang-github-sigstore-timestamp-authority, golang-github-sylabs-sif, golang-github-theupdateframework-go-tuf, groonga, groonga-normalizer-mysql, guestfs-tools, haxe, headache, hipblas, hipcub, hol-light, incant, incus, ironic-python-agent, js-of-ocaml, js-of-ocaml-ocamlbuild, kiwi, kiwi-boxed-plugin, lablgtk3, laby, lambda-term, laniakea, lava, ledit, libguestfs, libjjml-java, llama.cpp, llama.vim, lwt, lwt-ssl, meta-ocaml, meta-unison, metview, mlpost, morbig, morsmall, nbdkit, node-carto, node-hsluv, not-ocamlfind, nproc, nss-passwords, nurpawiki, obus, ocaml-afl-persistent, ocaml-alcotest, ocaml-asn1-combinators, ocaml-astring, ocaml-atd, ocaml-backoff, ocaml-base64, ocaml-batteries, ocaml-bos, ocaml-ca-certs, ocaml-caqti, ocaml-charinfo-width, ocaml-cohttp, ocaml-conduit, ocaml-containers, ocaml-crowbar, ocaml-crunch, ocaml-cry, ocaml-cstruct, ocaml-csv, ocaml-decimal, ocaml-digestif, ocaml-domain-local-await, ocaml-domain-local-timeout, ocaml-domain-name, ocaml-domainslib, ocaml-dscheck, ocaml-duration, ocaml-eio, ocaml-eqaf, ocaml-expect, ocaml-ezjsonm, ocaml-fmt, ocaml-fpath, ocaml-gen, ocaml-gettext, ocaml-gmap, ocaml-hex, ocaml-hmap, ocaml-inotify, ocaml-iomux, ocaml-ipaddr, ocaml-iter, ocaml-kcas, ocaml-kdf, ocaml-linenoise, ocaml-logs, ocaml-logs-syslog, ocaml-lru, ocaml-lwt-dllist, ocaml-markup, ocaml-mdx, ocaml-merlin, ocaml-mew-vi, ocaml-mirage-crypto, ocaml-mirage-kv, ocaml-mirage-kv-mem, ocaml-mirage-ptime, ocaml-monolith, ocaml-mtime, ocaml-multicore-bench, ocaml-multicore-magic, ocaml-multicoretests, ocaml-odoc, ocaml-ohex, ocaml-oseq, ocaml-patch, ocaml-pbkdf, ocaml-posix, ocaml-process, ocaml-psq, ocaml-ptime, ocaml-qcheck, ocaml-qtest, ocaml-randomconv, ocaml-rresult, ocaml-saturn, ocaml-sedlex, ocaml-spdx-licenses, ocaml-ssl, ocaml-stringext, ocaml-syslog-message, ocaml-testo, ocaml-thread-table, ocaml-unix-errno, ocaml-uri, ocaml-uring, ocaml-usb, ocaml-uuseg, ocaml-version, ocaml-websocket, ocaml-x509, ocamldap, ocamlgraph, ocamlviz, oci-seccomp-bpf-hook, ocplib-simplex, ocsigenserver, ocsipersist, ocurl, omd, opam, opam-0install-cudf, open-vm-tools, openstreetmap-carto, orpie, ott, oz, pgocaml, pkg-rocm-tools, podman, ppx-deriving-yojson, ppx-yojson-conv, ppx-yojson-conv-lib, prometheus, prometheus-postfix-exporter, prometheus-pushgateway, qemu-web-desktop, react, reactivedata, rekor, rocblas, rocfft, rocprim, rocq-micromega-plugin, rocq-stdlib, rocqnavi, rocsolver, rocsparse, rocthrust, rust-repro-env, sail-ocaml, sigstore-go, skeema, skopeo, ssh-tpm-agent, starpu, starpu-contrib, subuser, supermin, toil, tyxml, unison-2.53, utop, uuidm, virt-p2v, virt-top, virt-v2v, virtnbdbackup, whalebuilder, whisper.cpp, why3, witness, wyrd, yojson, zed, zeroinstall-injector. It depends (transitively) on golang-github-containerd-stargz-snapshotter, golang-github-frankban-quicktest, golang-github-go-git-go-git, golang-github-go-logr-logr, golang-github-go-quicktest-qt, golang-github-google-go-github, golang-github-googleapis-gax-go, golang-github-klauspost-compress, golang-github-peterbourgon-diskv, golang-github-prometheus-client-golang, golang-github-rogpeppe-go-internal, golang-k8s-apimachinery, golang-k8s-kube-openapi, golang-pgregory-rapid, affected by #1146000, #1146189, #1146192, #1146194, #1146195, #1146197, #1146199, #1146200, #1146203, #1146207, #1146219, #1146220, #1146223, #1146612. You should try to prevent the removal by fixing these RC bugs.
Created: 2026-09-04 Last update: 2026-09-15 01:02
Debci reports failed tests high
  • unstable: fail (log)
    The tests ran in 0:26:45
    Last run: 2026-09-07T23:08:26.000Z
    Previous status: unknown

  • testing: pass (log)
    The tests ran in 0:29:54
    Last run: 2026-09-14T13:42:40.000Z
    Previous status: unknown

  • stable: pass (log)
    The tests ran in 0:20:25
    Last run: 2026-07-15T19:37:13.000Z
    Previous status: unknown

Created: 2026-09-08 Last update: 2026-09-15 00:30
A new upstream version is available: 2.3.5 high
A new upstream version 2.3.5 is available, you should consider packaging it.
Created: 2026-07-17 Last update: 2026-09-14 21:31
3 security issues in trixie high

There are 3 open security issues in trixie.

3 important issues:
  • CVE-2026-46680: containerd is an open-source container runtime. In versions prior to 1.7.32, 2.0.9, 2.2.4 and 2.3.1, containers launched with a numeric User directive that cannot be parsed as a 32-bit integer are incorrectly treated as a username, leading to runAsNonRoot evasion. If a crafted image provides an /etc/passwd file mapping this large numeric string to root, the container ultimately runs as root (UID 0). This allows the Kubernetes runAsNonRoot restriction to be bypassed, causing unexpected behavior for environments that require containers to run as a non-root user. This issue has been fixed in versions 1.7.32, 2.0.9, 2.2.4 and 2.3.1.
  • CVE-2026-47262: containerd is an open-source container runtime. Versions prior to 1.7.33, 2.0.10, 2.1.9, 2.2.5 and 2.3.2, contain a vulnerability that allows a maliciously crafted image to cause a Denial of Service (DoS) condition. When creating a container from this image, memory exhaustion occurs, leading to an Out Of Memory (OOM) kill of the containerd process. This renders the container runtime API unavailable and can disrupt clients such as the Docker Engine or Kubernetes control-plane components. This issue has been fixed in versions 1.7.33, 2.0.10, 2.1.9, 2.2.5 and 2.3.2.
  • CVE-2026-53488: containerd is an open-source container runtime. In versions prior to 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10 the CRI plugin propagates labels from an image config (LABEL instruction in Dockerfile) to a container without validation. This may result in executing an arbitrary command on the host, via a plugin that consumes container labels for some operations. This issue has been fixed in versions 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10.
Created: 2026-06-19 Last update: 2026-09-06 04:33
1 security issue in sid high

There is 1 open security issue in sid.

1 important issue:
  • CVE-2026-46680: containerd is an open-source container runtime. In versions prior to 1.7.32, 2.0.9, 2.2.4 and 2.3.1, containers launched with a numeric User directive that cannot be parsed as a 32-bit integer are incorrectly treated as a username, leading to runAsNonRoot evasion. If a crafted image provides an /etc/passwd file mapping this large numeric string to root, the container ultimately runs as root (UID 0). This allows the Kubernetes runAsNonRoot restriction to be bypassed, causing unexpected behavior for environments that require containers to run as a non-root user. This issue has been fixed in versions 1.7.32, 2.0.9, 2.2.4 and 2.3.1.
Created: 2026-07-02 Last update: 2026-09-06 04:33
1 security issue in forky high

There is 1 open security issue in forky.

1 important issue:
  • CVE-2026-46680: containerd is an open-source container runtime. In versions prior to 1.7.32, 2.0.9, 2.2.4 and 2.3.1, containers launched with a numeric User directive that cannot be parsed as a 32-bit integer are incorrectly treated as a username, leading to runAsNonRoot evasion. If a crafted image provides an /etc/passwd file mapping this large numeric string to root, the container ultimately runs as root (UID 0). This allows the Kubernetes runAsNonRoot restriction to be bypassed, causing unexpected behavior for environments that require containers to run as a non-root user. This issue has been fixed in versions 1.7.32, 2.0.9, 2.2.4 and 2.3.1.
Created: 2026-07-02 Last update: 2026-09-06 04:33
3 security issues in bookworm high

There are 3 open security issues in bookworm.

3 important issues:
  • CVE-2026-46680: containerd is an open-source container runtime. In versions prior to 1.7.32, 2.0.9, 2.2.4 and 2.3.1, containers launched with a numeric User directive that cannot be parsed as a 32-bit integer are incorrectly treated as a username, leading to runAsNonRoot evasion. If a crafted image provides an /etc/passwd file mapping this large numeric string to root, the container ultimately runs as root (UID 0). This allows the Kubernetes runAsNonRoot restriction to be bypassed, causing unexpected behavior for environments that require containers to run as a non-root user. This issue has been fixed in versions 1.7.32, 2.0.9, 2.2.4 and 2.3.1.
  • CVE-2026-47262: containerd is an open-source container runtime. Versions prior to 1.7.33, 2.0.10, 2.1.9, 2.2.5 and 2.3.2, contain a vulnerability that allows a maliciously crafted image to cause a Denial of Service (DoS) condition. When creating a container from this image, memory exhaustion occurs, leading to an Out Of Memory (OOM) kill of the containerd process. This renders the container runtime API unavailable and can disrupt clients such as the Docker Engine or Kubernetes control-plane components. This issue has been fixed in versions 1.7.33, 2.0.10, 2.1.9, 2.2.5 and 2.3.2.
  • CVE-2026-53488: containerd is an open-source container runtime. In versions prior to 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10 the CRI plugin propagates labels from an image config (LABEL instruction in Dockerfile) to a container without validation. This may result in executing an arbitrary command on the host, via a plugin that consumes container labels for some operations. This issue has been fixed in versions 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10.
Created: 2026-06-19 Last update: 2026-09-06 04:33
3 security issues in bullseye high

There are 3 open security issues in bullseye.

3 important issues:
  • CVE-2026-46680: containerd is an open-source container runtime. In versions prior to 1.7.32, 2.0.9, 2.2.4 and 2.3.1, containers launched with a numeric User directive that cannot be parsed as a 32-bit integer are incorrectly treated as a username, leading to runAsNonRoot evasion. If a crafted image provides an /etc/passwd file mapping this large numeric string to root, the container ultimately runs as root (UID 0). This allows the Kubernetes runAsNonRoot restriction to be bypassed, causing unexpected behavior for environments that require containers to run as a non-root user. This issue has been fixed in versions 1.7.32, 2.0.9, 2.2.4 and 2.3.1.
  • CVE-2026-47262: containerd is an open-source container runtime. Versions prior to 1.7.33, 2.0.10, 2.1.9, 2.2.5 and 2.3.2, contain a vulnerability that allows a maliciously crafted image to cause a Denial of Service (DoS) condition. When creating a container from this image, memory exhaustion occurs, leading to an Out Of Memory (OOM) kill of the containerd process. This renders the container runtime API unavailable and can disrupt clients such as the Docker Engine or Kubernetes control-plane components. This issue has been fixed in versions 1.7.33, 2.0.10, 2.1.9, 2.2.5 and 2.3.2.
  • CVE-2026-53488: containerd is an open-source container runtime. In versions prior to 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10 the CRI plugin propagates labels from an image config (LABEL instruction in Dockerfile) to a container without validation. This may result in executing an arbitrary command on the host, via a plugin that consumes container labels for some operations. This issue has been fixed in versions 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10.
Created: 2026-06-19 Last update: 2026-09-01 01:32
Fails to build during reproducibility testing normal
A package building reproducibly enables third parties to verify that the source matches the distributed binaries. It has been identified that this source package produced different results, failed to build or had other issues in a test environment. Please read about how to improve the situation!
Created: 2026-06-23 Last update: 2026-09-14 22:19
Multiarch hinter reports 1 issue(s) normal
There are issues with the multiarch metadata for this package.
  • golang-github-containerd-containerd-api-dev could be marked Multi-Arch: foreign
Created: 2025-08-16 Last update: 2026-09-14 20:00
lintian reports 3 warnings normal
Lintian reports 3 warnings about this package. You should make the package lintian clean getting rid of them.
Created: 2026-04-03 Last update: 2026-09-13 20:32
news
[rss feed]
  • [2026-09-06] containerd 2.1.9+ds1-2 MIGRATED to testing (Debian testing watch)
  • [2026-08-31] Accepted containerd 2.1.9+ds1-2 (source) into unstable (Reinhard Tartler)
  • [2026-06-22] containerd 2.1.9+ds1-1 MIGRATED to testing (Debian testing watch)
  • [2026-06-19] Accepted containerd 2.1.9+ds1-1 (source) into unstable (Reinhard Tartler)
  • [2026-04-06] Accepted containerd 1.6.20~ds1-1+deb12u3 (source) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Arnaud Rebillout)
  • [2026-04-05] containerd 2.1.6+ds1-1 MIGRATED to testing (Debian testing watch)
  • [2026-04-02] Accepted containerd 2.1.6+ds1-1 (source) into unstable (Reinhard Tartler)
  • [2026-03-29] containerd 2.1.4~ds2-8 MIGRATED to testing (Debian testing watch)
  • [2026-03-23] Accepted containerd 2.1.4~ds2-8 (source) into unstable (Reinhard Tartler)
  • [2026-03-20] Accepted containerd 2.1.4~ds2-7 (source) into unstable (Reinhard Tartler)
  • [2026-03-20] Accepted containerd 2.1.4~ds2-6 (source) into experimental (Reinhard Tartler)
  • [2026-02-05] Accepted containerd 1.4.13~ds1-1~deb11u6 (source) into oldoldstable-security (Arnaud Rebillout)
  • [2026-01-11] Accepted containerd 2.1.4~ds2-5 (source) into experimental (Reinhard Tartler)
  • [2026-01-10] Accepted containerd 2.1.4~ds2-4 (source) into experimental (Reinhard Tartler)
  • [2026-01-03] Accepted containerd 2.1.4~ds2-3 (source) into experimental (Reinhard Tartler)
  • [2026-01-02] Accepted containerd 2.1.4~ds2-2 (source) into experimental (Reinhard Tartler)
  • [2025-12-06] Accepted containerd 1.7.24~ds1-6+deb13u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Reinhard Tartler)
  • [2025-12-05] Accepted containerd 1.6.20~ds1-1+deb12u2 (source) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Reinhard Tartler)
  • [2025-12-02] Accepted containerd 1.7.24~ds1-6+deb13u1 (source) into stable-security (Debian FTP Masters) (signed by: Reinhard Tartler)
  • [2025-12-02] Accepted containerd 1.6.20~ds1-1+deb12u2 (source) into oldstable-security (Debian FTP Masters) (signed by: Reinhard Tartler)
  • [2025-11-10] containerd 1.7.24~ds1-10 MIGRATED to testing (Debian testing watch)
  • [2025-11-08] Accepted containerd 1.7.24~ds1-10 (source) into unstable (Reinhard Tartler)
  • [2025-11-07] Accepted containerd 1.7.24~ds1-9 (source) into unstable (Reinhard Tartler)
  • [2025-08-20] containerd 1.7.24~ds1-8 MIGRATED to testing (Debian testing watch)
  • [2025-08-15] Accepted containerd 1.7.24~ds1-8 (source) into unstable (Reinhard Tartler)
  • [2025-08-14] Accepted containerd 1.7.24~ds1-7 (all amd64 source) into experimental (Debian FTP Masters) (signed by: Reinhard Tartler)
  • [2025-05-15] containerd 1.7.24~ds1-6 MIGRATED to testing (Debian testing watch)
  • [2025-05-04] Accepted containerd 1.4.13~ds1-1~deb11u5 (source) into oldstable-security (Andreas Henriksson)
  • [2025-04-29] Accepted containerd 1.7.24~ds1-6 (source) into unstable (Andreas Henriksson)
  • [2025-04-14] containerd 1.7.24~ds1-5 MIGRATED to testing (Debian testing watch)
  • 1
  • 2
bugs [bug history graph]
  • all: 3
  • RC: 1
  • I&N: 2
  • M&W: 0
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian (0, 3)
  • buildd: logs, reproducibility
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 1.7.24~ds1-10ubuntu1
  • 2 bugs
  • patches for 1.7.24~ds1-10ubuntu1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing