Debian Package Tracker
Register | Log in
Subscribe

criu

checkpoint and restore in userspace

Choose email to subscribe with

general
  • source: criu (main)
  • version: 4.2.1-1
  • maintainer: Salvatore Bonaccorso (DMD) (LowNMU)
  • arch: all amd64 arm64 ppc64el riscv64 s390x
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • oldstable: 3.17.1-2+deb12u2
  • stable: 4.1.1-1
  • testing: 4.2-6
  • unstable: 4.2.1-1
versioned links
  • 3.17.1-2+deb12u2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 4.1.1-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 4.2-6: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 4.2.1-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • criu
  • libcompel-dev
  • libcompel1
  • libcriu-dev
  • libcriu2
  • python3-pycriu
action needed
Debci reports failed tests high
  • unstable: fail (log)
    The tests ran in 0:21:03
    Last run: 2026-07-09T18:46:13.000Z
    Previous status: unknown

  • testing: fail (log)
    The tests ran in 0:18:48
    Last run: 2026-07-20T16:44:53.000Z
    Previous status: unknown

  • stable: pass (log)
    The tests ran in 0:20:51
    Last run: 2026-07-15T18:30:18.000Z
    Previous status: unknown

Created: 2026-07-09 Last update: 2026-08-04 07:31
1 security issue in trixie high

There is 1 open security issue in trixie.

1 important issue:
  • CVE-2026-18107: A flaw was found in CRIU's handling of restartable sequences (rseq) during checkpoint/restore. A malicious process inside a container can register an rseq critical section that hijacks CRIU's parasite code injection during checkpoint, allowing it to spoof the process credentials saved in the checkpoint image. On restore, the container process gains elevated capabilities and zeroed UIDs/GIDs. The practical impact on Red Hat products is limited by several factors: checkpoint/restore requires root privileges (podman) or cluster-admin RBAC (OpenShift) to trigger and cannot be initiated from within the container itself; on OpenShift prior to 4.17 the feature required explicit opt-in, and on 4.17+ the kubelet checkpoint API RBAC is not configured by default; OpenShift enforces user namespaces by default for regular workloads (hostUsers is gated behind admin-only SCCs), which makes the spoofed capabilities namespace-scoped and ineffective for privilege escalation; SELinux type enforcement (container_t) blocks privilege transitions independently of capabilities; seccomp filters persist through checkpoint/restore and cannot be corrupted via the parasite; and kernel mount namespace ownership checks on RHEL 9/10 kernels prevent mount-based container escape even with spoofed capabilities.
Created: 2026-07-29 Last update: 2026-08-02 20:32
1 security issue in bookworm high

There is 1 open security issue in bookworm.

1 important issue:
  • CVE-2026-18107: A flaw was found in CRIU's handling of restartable sequences (rseq) during checkpoint/restore. A malicious process inside a container can register an rseq critical section that hijacks CRIU's parasite code injection during checkpoint, allowing it to spoof the process credentials saved in the checkpoint image. On restore, the container process gains elevated capabilities and zeroed UIDs/GIDs. The practical impact on Red Hat products is limited by several factors: checkpoint/restore requires root privileges (podman) or cluster-admin RBAC (OpenShift) to trigger and cannot be initiated from within the container itself; on OpenShift prior to 4.17 the feature required explicit opt-in, and on 4.17+ the kubelet checkpoint API RBAC is not configured by default; OpenShift enforces user namespaces by default for regular workloads (hostUsers is gated behind admin-only SCCs), which makes the spoofed capabilities namespace-scoped and ineffective for privilege escalation; SELinux type enforcement (container_t) blocks privilege transitions independently of capabilities; seccomp filters persist through checkpoint/restore and cannot be corrupted via the parasite; and kernel mount namespace ownership checks on RHEL 9/10 kernels prevent mount-based container escape even with spoofed capabilities.
Created: 2026-07-29 Last update: 2026-08-02 20:32
Multiarch hinter reports 1 issue(s) normal
There are issues with the multiarch metadata for this package.
  • libcriu-dev could be marked Multi-Arch: same
Created: 2026-07-21 Last update: 2026-08-04 07:01
lintian reports 23 warnings normal
Lintian reports 23 warnings about this package. You should make the package lintian clean getting rid of them.
Created: 2026-04-04 Last update: 2026-04-07 23:31
testing migrations
  • excuses:
    • Migration status for criu (4.2-6 to 4.2.1-1): Waiting for test results or another package, or too young (no action required now - check later)
    • Issues preventing migration:
    • ∙ ∙ Too young, only 4 of 5 days old
    • Additional info (not blocking):
    • ∙ ∙ Piuparts tested OK - https://piuparts.debian.org/sid/source/c/criu.html
    • ∙ ∙ Autopkgtest skipped on armhf: not installable (which is allowed)
    • ∙ ∙ Autopkgtest skipped on i386: not installable (which is allowed)
    • ∙ ∙ Autopkgtest skipped on loong64: not installable (which is allowed)
    • ∙ ∙ Autopkgtest for criu/4.2.1-1: amd64: Pass, arm64: No tests, superficial or marked flaky ♻, ppc64el: No tests, superficial or marked flaky ♻ (reference ♻), riscv64: No tests, superficial or marked flaky ♻ (reference ♻), s390x: No tests, superficial or marked flaky ♻
    • ∙ ∙ Reproduced on amd64 - info
    • ∙ ∙ Reproduced on arm64 - info
    • ∙ ∙ Reproduced on armhf - info
    • ∙ ∙ Reproduced on i386 - info
    • Not considered
news
[rss feed]
  • [2026-07-30] Accepted criu 4.2.1-1 (source) into unstable (Salvatore Bonaccorso)
  • [2026-07-26] criu 4.2-6 MIGRATED to testing (Debian testing watch)
  • [2026-07-20] Accepted criu 4.2-6 (source) into unstable (Salvatore Bonaccorso)
  • [2026-07-20] Accepted criu 4.2-5 (source) into unstable (Salvatore Bonaccorso)
  • [2026-05-25] criu 4.2-4 MIGRATED to testing (Debian testing watch)
  • [2026-05-17] Accepted criu 4.2-4 (source) into unstable (Salvatore Bonaccorso)
  • [2026-04-09] criu 4.2-3 MIGRATED to testing (Debian testing watch)
  • [2026-04-04] Accepted criu 4.2-3 (source) into unstable (Salvatore Bonaccorso)
  • [2026-03-17] criu 4.2-2 MIGRATED to testing (Debian testing watch)
  • [2026-03-11] Accepted criu 4.2-2 (source) into unstable (Salvatore Bonaccorso)
  • [2025-11-21] criu 4.2-1 MIGRATED to testing (Debian testing watch)
  • [2025-11-15] Accepted criu 4.2-1 (source) into unstable (Salvatore Bonaccorso)
  • [2025-11-08] criu 4.1.1-3 MIGRATED to testing (Debian testing watch)
  • [2025-11-02] Accepted criu 4.1.1-3 (source) into unstable (Salvatore Bonaccorso)
  • [2025-08-28] criu 4.1.1-2 MIGRATED to testing (Debian testing watch)
  • [2025-08-25] Accepted criu 3.17.1-2+deb12u2 (source) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Salvatore Bonaccorso)
  • [2025-08-22] Accepted criu 4.1.1-2 (source) into unstable (Salvatore Bonaccorso)
  • [2025-08-17] Accepted criu 4.1.1-2~exp1 (source) into experimental (Salvatore Bonaccorso)
  • [2025-08-01] criu 4.1.1-1 MIGRATED to testing (Debian testing watch)
  • [2025-07-30] Accepted criu 4.1.1-1 (source) into unstable (Salvatore Bonaccorso)
  • [2025-04-02] criu 4.1-1 MIGRATED to testing (Debian testing watch)
  • [2025-03-27] Accepted criu 4.1-1 (source) into unstable (Salvatore Bonaccorso)
  • [2025-03-26] Accepted criu 4.1-1~exp1 (source) into experimental (Salvatore Bonaccorso)
  • [2025-03-16] criu 4.0-4 MIGRATED to testing (Debian testing watch)
  • [2025-03-10] Accepted criu 4.0-4 (source) into unstable (Salvatore Bonaccorso)
  • [2025-01-15] criu 4.0-3 MIGRATED to testing (Debian testing watch)
  • [2025-01-09] Accepted criu 4.0-3 (source) into unstable (Salvatore Bonaccorso)
  • [2024-12-16] criu 4.0-2 MIGRATED to testing (Debian testing watch)
  • [2024-12-11] Accepted criu 4.0-2 (source) into unstable (Salvatore Bonaccorso)
  • [2024-12-11] criu 4.0-1 MIGRATED to testing (Debian testing watch)
  • 1
  • 2
bugs [bug history graph]
  • all: 2
  • RC: 0
  • I&N: 0
  • M&W: 2
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian (0, 23)
  • buildd: logs, reproducibility, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 4.2-1ubuntu2
  • patches for 4.2-1ubuntu2

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing