Debian Package Tracker
Register | Log in
Subscribe

containerd

open and reliable container runtime

Choose email to subscribe with

general
  • source: containerd (main)
  • version: 2.1.9+ds1-5
  • maintainer: Debian Go Packaging Team (DMD)
  • uploaders: Reinhard Tartler [DMD] – Tianon Gravi [DMD] – Tim Potter [DMD] – Shengjing Zhu [DMD]
  • arch: all
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 1.4.13~ds1-1~deb11u4
  • o-o-sec: 1.4.13~ds1-1~deb11u6
  • oldstable: 1.6.20~ds1-1+deb12u3
  • old-sec: 1.6.20~ds1-1+deb12u2
  • stable: 1.7.24~ds1-6+deb13u1
  • stable-sec: 1.7.24~ds1-6+deb13u1
  • testing: 2.1.9+ds1-3
  • unstable: 2.1.9+ds1-5
versioned links
  • 1.4.13~ds1-1~deb11u4: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.4.13~ds1-1~deb11u6: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.6.20~ds1-1+deb12u2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.6.20~ds1-1+deb12u3: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.7.24~ds1-6+deb13u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.1.9+ds1-3: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.1.9+ds1-5: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • containerd (1 bugs: 0, 1, 0, 0)
  • golang-github-containerd-containerd-api-dev
  • golang-github-containerd-containerd-dev
action needed
Problems while searching for a new upstream version high
uscan had problems while searching for a new upstream version:
In watchfile debian/watch, reading webpage
  https://api.github.com/repos/containerd/containerd/git/matching-refs/tags/ failed: 500 Internal Server Error
Created: 2026-10-09 Last update: 2026-10-09 20:30
5 security issues in trixie high

There are 5 open security issues in trixie.

5 important issues:
  • CVE-2026-46680: containerd is an open-source container runtime. In versions prior to 1.7.32, 2.0.9, 2.2.4 and 2.3.1, containers launched with a numeric User directive that cannot be parsed as a 32-bit integer are incorrectly treated as a username, leading to runAsNonRoot evasion. If a crafted image provides an /etc/passwd file mapping this large numeric string to root, the container ultimately runs as root (UID 0). This allows the Kubernetes runAsNonRoot restriction to be bypassed, causing unexpected behavior for environments that require containers to run as a non-root user. This issue has been fixed in versions 1.7.32, 2.0.9, 2.2.4 and 2.3.1.
  • CVE-2026-47262: containerd is an open-source container runtime. Versions prior to 1.7.33, 2.0.10, 2.1.9, 2.2.5 and 2.3.2, contain a vulnerability that allows a maliciously crafted image to cause a Denial of Service (DoS) condition. When creating a container from this image, memory exhaustion occurs, leading to an Out Of Memory (OOM) kill of the containerd process. This renders the container runtime API unavailable and can disrupt clients such as the Docker Engine or Kubernetes control-plane components. This issue has been fixed in versions 1.7.33, 2.0.10, 2.1.9, 2.2.5 and 2.3.2.
  • CVE-2026-53488: containerd is an open-source container runtime. In versions prior to 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10 the CRI plugin propagates labels from an image config (LABEL instruction in Dockerfile) to a container without validation. This may result in executing an arbitrary command on the host, via a plugin that consumes container labels for some operations. This issue has been fixed in versions 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10.
  • CVE-2026-53493: containerd is an open-source container runtime. Prior to versions 1.7.36, 2.0.13, 2.2.9, 2.3.6, and 2.4.1, a crafted OCI index graph can force very high CPU/memory usage during PullImage (before container start), causing long ContainerCreating stalls and, at larger sizes, node/runtime instability. Versions 1.7.36, 2.0.13, 2.2.9, 2.3.6, and 2.4.1 fix the issue.
  • CVE-2026-53495: containerd is an open-source container runtime. Prior to 1.7.35, 2.0.12, 2.2.8, and 2.3.5, containerd on Linux with the CRI plugin enabled can indefinitely block the drainExecSyncIO goroutine in internal/cri/server/container_execsync.go when CRI ExecSync is used by exec probes or lifecycle hooks that launch long-lived background child processes retaining standard input and output pipes. The input and output drain phase has no default timeout and did not stop when the request context was canceled, so repeated ExecSync invocations can accumulate blocked goroutines and host memory. The resulting resource exhaustion can cause the OOM killer to terminate containerd, leaving the container runtime unavailable until restart. Deployments not using containerd's CRI implementation and containers not running on Linux are not affected. This issue is fixed in versions 1.7.35, 2.0.12, 2.2.8, and 2.3.5.
Created: 2026-06-19 Last update: 2026-10-05 08:30
2 security issues in forky high

There are 2 open security issues in forky.

2 important issues:
  • CVE-2026-53493: containerd is an open-source container runtime. Prior to versions 1.7.36, 2.0.13, 2.2.9, 2.3.6, and 2.4.1, a crafted OCI index graph can force very high CPU/memory usage during PullImage (before container start), causing long ContainerCreating stalls and, at larger sizes, node/runtime instability. Versions 1.7.36, 2.0.13, 2.2.9, 2.3.6, and 2.4.1 fix the issue.
  • CVE-2026-53495: containerd is an open-source container runtime. Prior to 1.7.35, 2.0.12, 2.2.8, and 2.3.5, containerd on Linux with the CRI plugin enabled can indefinitely block the drainExecSyncIO goroutine in internal/cri/server/container_execsync.go when CRI ExecSync is used by exec probes or lifecycle hooks that launch long-lived background child processes retaining standard input and output pipes. The input and output drain phase has no default timeout and did not stop when the request context was canceled, so repeated ExecSync invocations can accumulate blocked goroutines and host memory. The resulting resource exhaustion can cause the OOM killer to terminate containerd, leaving the container runtime unavailable until restart. Deployments not using containerd's CRI implementation and containers not running on Linux are not affected. This issue is fixed in versions 1.7.35, 2.0.12, 2.2.8, and 2.3.5.
Created: 2026-07-02 Last update: 2026-10-05 08:30
5 security issues in bookworm high

There are 5 open security issues in bookworm.

5 important issues:
  • CVE-2026-46680: containerd is an open-source container runtime. In versions prior to 1.7.32, 2.0.9, 2.2.4 and 2.3.1, containers launched with a numeric User directive that cannot be parsed as a 32-bit integer are incorrectly treated as a username, leading to runAsNonRoot evasion. If a crafted image provides an /etc/passwd file mapping this large numeric string to root, the container ultimately runs as root (UID 0). This allows the Kubernetes runAsNonRoot restriction to be bypassed, causing unexpected behavior for environments that require containers to run as a non-root user. This issue has been fixed in versions 1.7.32, 2.0.9, 2.2.4 and 2.3.1.
  • CVE-2026-47262: containerd is an open-source container runtime. Versions prior to 1.7.33, 2.0.10, 2.1.9, 2.2.5 and 2.3.2, contain a vulnerability that allows a maliciously crafted image to cause a Denial of Service (DoS) condition. When creating a container from this image, memory exhaustion occurs, leading to an Out Of Memory (OOM) kill of the containerd process. This renders the container runtime API unavailable and can disrupt clients such as the Docker Engine or Kubernetes control-plane components. This issue has been fixed in versions 1.7.33, 2.0.10, 2.1.9, 2.2.5 and 2.3.2.
  • CVE-2026-53488: containerd is an open-source container runtime. In versions prior to 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10 the CRI plugin propagates labels from an image config (LABEL instruction in Dockerfile) to a container without validation. This may result in executing an arbitrary command on the host, via a plugin that consumes container labels for some operations. This issue has been fixed in versions 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10.
  • CVE-2026-53493: containerd is an open-source container runtime. Prior to versions 1.7.36, 2.0.13, 2.2.9, 2.3.6, and 2.4.1, a crafted OCI index graph can force very high CPU/memory usage during PullImage (before container start), causing long ContainerCreating stalls and, at larger sizes, node/runtime instability. Versions 1.7.36, 2.0.13, 2.2.9, 2.3.6, and 2.4.1 fix the issue.
  • CVE-2026-53495: containerd is an open-source container runtime. Prior to 1.7.35, 2.0.12, 2.2.8, and 2.3.5, containerd on Linux with the CRI plugin enabled can indefinitely block the drainExecSyncIO goroutine in internal/cri/server/container_execsync.go when CRI ExecSync is used by exec probes or lifecycle hooks that launch long-lived background child processes retaining standard input and output pipes. The input and output drain phase has no default timeout and did not stop when the request context was canceled, so repeated ExecSync invocations can accumulate blocked goroutines and host memory. The resulting resource exhaustion can cause the OOM killer to terminate containerd, leaving the container runtime unavailable until restart. Deployments not using containerd's CRI implementation and containers not running on Linux are not affected. This issue is fixed in versions 1.7.35, 2.0.12, 2.2.8, and 2.3.5.
Created: 2026-06-19 Last update: 2026-10-05 08:30
3 security issues in bullseye high

There are 3 open security issues in bullseye.

3 important issues:
  • CVE-2026-46680: containerd is an open-source container runtime. In versions prior to 1.7.32, 2.0.9, 2.2.4 and 2.3.1, containers launched with a numeric User directive that cannot be parsed as a 32-bit integer are incorrectly treated as a username, leading to runAsNonRoot evasion. If a crafted image provides an /etc/passwd file mapping this large numeric string to root, the container ultimately runs as root (UID 0). This allows the Kubernetes runAsNonRoot restriction to be bypassed, causing unexpected behavior for environments that require containers to run as a non-root user. This issue has been fixed in versions 1.7.32, 2.0.9, 2.2.4 and 2.3.1.
  • CVE-2026-47262: containerd is an open-source container runtime. Versions prior to 1.7.33, 2.0.10, 2.1.9, 2.2.5 and 2.3.2, contain a vulnerability that allows a maliciously crafted image to cause a Denial of Service (DoS) condition. When creating a container from this image, memory exhaustion occurs, leading to an Out Of Memory (OOM) kill of the containerd process. This renders the container runtime API unavailable and can disrupt clients such as the Docker Engine or Kubernetes control-plane components. This issue has been fixed in versions 1.7.33, 2.0.10, 2.1.9, 2.2.5 and 2.3.2.
  • CVE-2026-53488: containerd is an open-source container runtime. In versions prior to 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10 the CRI plugin propagates labels from an image config (LABEL instruction in Dockerfile) to a container without validation. This may result in executing an arbitrary command on the host, via a plugin that consumes container labels for some operations. This issue has been fixed in versions 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10.
Created: 2026-06-19 Last update: 2026-09-01 01:32
Multiarch hinter reports 1 issue(s) normal
There are issues with the multiarch metadata for this package.
  • golang-github-containerd-containerd-api-dev could be marked Multi-Arch: foreign
Created: 2025-08-16 Last update: 2026-10-09 15:30
Fails to build during reproducibility testing normal
A package building reproducibly enables third parties to verify that the source matches the distributed binaries. It has been identified that this source package produced different results, failed to build or had other issues in a test environment. Please read about how to improve the situation!
Created: 2026-06-23 Last update: 2026-10-09 15:30
1 open merge request in Salsa normal
There is 1 open merge request for this package on Salsa. You should consider reviewing and/or merging these merge requests.
Created: 2026-09-28 Last update: 2026-09-28 23:00
lintian reports 3 warnings normal
Lintian reports 3 warnings about this package. You should make the package lintian clean getting rid of them.
Created: 2026-04-03 Last update: 2026-09-13 20:32
testing migrations
  • excuses:
    • Migration status for containerd (2.1.9+ds1-3 to 2.1.9+ds1-5): BLOCKED: Rejected/violates migration policy/introduces a regression
    • Issues preventing migration:
    • ∙ ∙ Autopkgtest for containerd/2.1.9+ds1-5: amd64: Pass, arm64: Failed (not a regression) ♻ (reference ♻), armhf: Failed (not a regression) ♻ (reference ♻), i386: Failed (not a regression) ♻ (reference ♻), ppc64el: Failed (not a regression) ♻ (reference ♻), riscv64: Failed (not a regression) ♻ (reference ♻), s390x: Failed (not a regression) ♻ (reference ♻)
    • ∙ ∙ Autopkgtest for golang-github-awslabs-soci-snapshotter/0.4.1-6: amd64: Pass, arm64: Pass, armhf: Failed (not a regression) ♻ (reference ♻), i386: Failed (not a regression) ♻ (reference ♻), ppc64el: Pass, riscv64: Regression ♻ (reference ♻), s390x: Pass
    • Additional info (not blocking):
    • ∙ ∙ Piuparts tested OK - https://piuparts.debian.org/sid/source/c/containerd.html
    • ∙ ∙ Reproduced on amd64 - info
    • ∙ ∙ Reproduced on arm64 - info
    • ∙ ∙ Reproduced on armhf - info
    • ∙ ∙ Reproduced on i386 - info
    • ∙ ∙ 5 days old (needed 5 days)
    • Not considered
news
[rss feed]
  • [2026-10-04] Accepted containerd 2.1.9+ds1-5 (source) into unstable (Reinhard Tartler)
  • [2026-10-03] Accepted containerd 2.1.9+ds1-4 (source) into unstable (Reinhard Tartler)
  • [2026-09-22] containerd 2.1.9+ds1-3 MIGRATED to testing (Debian testing watch)
  • [2026-09-16] Accepted containerd 2.1.9+ds1-3 (source) into unstable (Reinhard Tartler)
  • [2026-09-06] containerd 2.1.9+ds1-2 MIGRATED to testing (Debian testing watch)
  • [2026-08-31] Accepted containerd 2.1.9+ds1-2 (source) into unstable (Reinhard Tartler)
  • [2026-06-22] containerd 2.1.9+ds1-1 MIGRATED to testing (Debian testing watch)
  • [2026-06-19] Accepted containerd 2.1.9+ds1-1 (source) into unstable (Reinhard Tartler)
  • [2026-04-06] Accepted containerd 1.6.20~ds1-1+deb12u3 (source) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Arnaud Rebillout)
  • [2026-04-05] containerd 2.1.6+ds1-1 MIGRATED to testing (Debian testing watch)
  • [2026-04-02] Accepted containerd 2.1.6+ds1-1 (source) into unstable (Reinhard Tartler)
  • [2026-03-29] containerd 2.1.4~ds2-8 MIGRATED to testing (Debian testing watch)
  • [2026-03-23] Accepted containerd 2.1.4~ds2-8 (source) into unstable (Reinhard Tartler)
  • [2026-03-20] Accepted containerd 2.1.4~ds2-7 (source) into unstable (Reinhard Tartler)
  • [2026-03-20] Accepted containerd 2.1.4~ds2-6 (source) into experimental (Reinhard Tartler)
  • [2026-02-05] Accepted containerd 1.4.13~ds1-1~deb11u6 (source) into oldoldstable-security (Arnaud Rebillout)
  • [2026-01-11] Accepted containerd 2.1.4~ds2-5 (source) into experimental (Reinhard Tartler)
  • [2026-01-10] Accepted containerd 2.1.4~ds2-4 (source) into experimental (Reinhard Tartler)
  • [2026-01-03] Accepted containerd 2.1.4~ds2-3 (source) into experimental (Reinhard Tartler)
  • [2026-01-02] Accepted containerd 2.1.4~ds2-2 (source) into experimental (Reinhard Tartler)
  • [2025-12-06] Accepted containerd 1.7.24~ds1-6+deb13u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Reinhard Tartler)
  • [2025-12-05] Accepted containerd 1.6.20~ds1-1+deb12u2 (source) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Reinhard Tartler)
  • [2025-12-02] Accepted containerd 1.7.24~ds1-6+deb13u1 (source) into stable-security (Debian FTP Masters) (signed by: Reinhard Tartler)
  • [2025-12-02] Accepted containerd 1.6.20~ds1-1+deb12u2 (source) into oldstable-security (Debian FTP Masters) (signed by: Reinhard Tartler)
  • [2025-11-10] containerd 1.7.24~ds1-10 MIGRATED to testing (Debian testing watch)
  • [2025-11-08] Accepted containerd 1.7.24~ds1-10 (source) into unstable (Reinhard Tartler)
  • [2025-11-07] Accepted containerd 1.7.24~ds1-9 (source) into unstable (Reinhard Tartler)
  • [2025-08-20] containerd 1.7.24~ds1-8 MIGRATED to testing (Debian testing watch)
  • [2025-08-15] Accepted containerd 1.7.24~ds1-8 (source) into unstable (Reinhard Tartler)
  • [2025-08-14] Accepted containerd 1.7.24~ds1-7 (all amd64 source) into experimental (Debian FTP Masters) (signed by: Reinhard Tartler)
  • 1
  • 2
bugs [bug history graph]
  • all: 1
  • RC: 0
  • I&N: 1
  • M&W: 0
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian (0, 3)
  • buildd: logs, reproducibility
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 2.1.9+ds1-5ubuntu1
  • 2 bugs
  • patches for 2.1.9+ds1-3ubuntu1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing