UbuntuUpdates.org

Package "containerd"

Name: containerd

Description:

daemon to control runC

Latest version: 2.2.1-0ubuntu1~25.10.2
Release: questing (25.10)
Level: security
Repository: main
Head package: containerd-app
Homepage: https://containerd.io

Links


Download "containerd"


Other versions of "containerd" in Questing

Repository Area Version
base main 2.1.3-0ubuntu3
base universe 1.7.24~ds1-8ubuntu1
security universe 1.7.24~ds1-8ubuntu1.1
updates universe 1.7.24~ds1-8ubuntu1.1
updates main 2.2.1-0ubuntu1~25.10.2

Changelog

Version: 2.2.1-0ubuntu1~25.10.2 2026-06-25 13:07:32 UTC

  containerd-app (2.2.1-0ubuntu1~25.10.2) questing-security; urgency=high

  * SECURITY UPDATE: HTTP/2 SETTINGS frame infinite loop (vendored
    golang.org/x/net)
    - debian/patches/CVE-2026-33814.patch: move s.Valid() check before
      switch in ForeachSetting callback
    - CVE-2026-33814
  * SECURITY UPDATE: Uncontrolled Resource Consumption via unbounded
    group parsing
    - debian/patches/CVE-2026-47262.patch: bound user-database file
      reads in openUserFile, reject non-regular files
    - CVE-2026-47262
  * SECURITY UPDATE: Insufficient Verification of Data Authenticity in
    CRI checkpoint import
    - debian/patches/CVE-2026-50195.patch: remove re-tagging of restored
      checkpoint base images
    - CVE-2026-50195
  * SECURITY UPDATE: Reserved label propagation from image configs
    - debian/patches/CVE-2026-53488.patch: filter containerd.io/ and
      io.cri-containerd labels from image config
    - CVE-2026-53488
  * SECURITY UPDATE: UNIX Symbolic Link Following in CRI checkpoint
    restore
    - debian/patches/CVE-2026-53489.patch: add copyNoFollow,
      checkpointArchiveEntryAllowed, assertCheckpointDirSafe; use
      dedicated restore subdirectory
    - CVE-2026-53489
  * SECURITY UPDATE: Improper Input Validation of CDI annotations in
    checkpoint restore
    - debian/patches/CVE-2026-53492.patch: filter cdi.k8s.io
      annotations on checkpoint restore
    - CVE-2026-53492

 -- Eduardo Barretto <email address hidden> Mon, 22 Jun 2026 18:09:34 +0200

Source diff to previous version
CVE-2026-33814 When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE

Version: 2.1.3-0ubuntu3.1 2026-01-29 11:00:27 UTC

  containerd-app (2.1.3-0ubuntu3.1) questing-security; urgency=medium

  * SECURITY UPDATE: local priv escalation vulnerability
    - debian/patches/CVE-2024-25621.patch: Fix directory permissions
    - CVE-2024-25621
  * SECURITY UPDATE: denial of service
    - debian/patches/CVE-2025-64329.patch: fix goroutine leak of container
      attach
    - CVE-2025-64329

 -- Nishit Majithia <email address hidden> Wed, 28 Jan 2026 10:38:22 +0530

CVE-2024-25621 containerd is an open-source container runtime. Versions 0.1.0 through 1.7.28, 2.0.0-beta.0 through 2.0.6, 2.1.0-beta.0 through 2.1.4 and 2.2.0-beta.
CVE-2025-64329 containerd is an open-source container runtime. Versions 1.7.28 and below, 2.0.0-beta.0 through 2.0.6, 2.1.0-beta.0 through 2.1.4, and 2.2.0-beta.0 t



About   -   Send Feedback to @ubuntu_updates