Skip to content

chore(deps): update module github.com/containerd/containerd/v2 to v2.3.6 [security] - #2185

Merged
lgecse merged 1 commit into
mainfrom
renovate/go-github.com-containerd-containerd-v2-vulnerability
Sep 29, 2026
Merged

lgecse merged 1 commit into
mainfrom
renovate/go-github.com-containerd-containerd-v2-vulnerability

Conversation

@agntcy-automation

@agntcy-automation agntcy-automation Bot commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
github.com/containerd/containerd/v2 v2.3.5 → v2.3.6 age confidence

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.

GitHub Vulnerability Alerts

CVE-2026-53493

Impact

A vulnerability exists in containerd's image pull handlers where a crafted OCI image index containing deeply nested or heavily fanned-out descriptor graphs can cause unbounded CPU and memory consumption. During the PullImage operation, the recursive traversal and processing of child descriptors lack sufficient depth and breadth limits, and fail to adequately deduplicate identical descriptors. This unbounded traversal leads to excessive resource allocation.

Consequently, pulling a malicious image reference can result in prolonged stalls during container creation and significant resource pressure on the host system. This issue occurs entirely during the image pull phase, prior to any container execution.

Patches

This bug has been fixed in containerd 2.4.1, 2.3.6, 2.2.9, 2.0.13, and 1.7.36. Users should update to these versions to resolve the issue.

Workarounds

There are no known workarounds for this issue. Users are advised to only pull trusted images from known registries until the patch can be applied.

Credits

The containerd project would like to thank Jakub Ciolek at ElevenLabs and @​jlgore who independently discovered and responsibly disclosed this issue in accordance with the containerd security policy.

For more information

If you have any questions or comments about this advisory:

To report a security issue in containerd:


Containerd has image-pull DoS via crafted OCI index graph amplification

CVE-2026-53493 / GHSA-pg57-6jwg-q645

More information

Details

Impact

A vulnerability exists in containerd's image pull handlers where a crafted OCI image index containing deeply nested or heavily fanned-out descriptor graphs can cause unbounded CPU and memory consumption. During the PullImage operation, the recursive traversal and processing of child descriptors lack sufficient depth and breadth limits, and fail to adequately deduplicate identical descriptors. This unbounded traversal leads to excessive resource allocation.

Consequently, pulling a malicious image reference can result in prolonged stalls during container creation and significant resource pressure on the host system. This issue occurs entirely during the image pull phase, prior to any container execution.

Patches

This bug has been fixed in containerd 2.4.1, 2.3.6, 2.2.9, 2.0.13, and 1.7.36. Users should update to these versions to resolve the issue.

Workarounds

There are no known workarounds for this issue. Users are advised to only pull trusted images from known registries until the patch can be applied.

Credits

The containerd project would like to thank Jakub Ciolek at ElevenLabs and @​jlgore who independently discovered and responsibly disclosed this issue in accordance with the containerd security policy.

For more information

If you have any questions or comments about this advisory:

To report a security issue in containerd:

Severity

  • CVSS Score: 6.9 / 10 (Medium)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Release Notes

containerd/containerd (github.com/containerd/containerd/v2)

v2.3.6: containerd 2.3.6

Compare Source

Welcome to the v2.3.6 release of containerd!

The sixth patch release for containerd 2.3 contains various fixes
and updates including a security patch.

Security Updates
Highlights
Container Runtime Interface (CRI)
  • Fix bug where container creation failed when SELinux relabeling was unsupported by the filesystem (#​14211)
  • Enable mount manager for image mounts in CRI (#​14147)
Image Storage
  • Ensure all layers are fetched when multiple manifests in an index share a config descriptor (#​14139)
Runtime
  • Avoid unexpected mutation of mount options in mount helpers (#​14192)
  • Mask /proc/interrupts and CPU thermal throttle sysfs paths in Linux containers by default (#​14144)

Please try out the release binaries and report any issues at
https://github.com/containerd/containerd/issues.

Contributors
  • Paweł Gronowski
  • Samuel Karp
  • Chris Henzie
  • Maksym Pavlenko
  • Wei Fu
  • Gao Xiang
  • Nan Liu
Changes
26 commits

  • 086fc0d40e Prepare release notes for v2.3.6
  • 3e3b3daabc Merge commit from fork
  • 03fbef37da Bound Walk references
  • bfe167214b Bound Dispatch concurrency and references
  • Fix input mutation in mount option helpers (#​14192)
    • 5f17a29a9b core/mount: Keep lazy copy for filtered options
    • 49796574fb core/mount: Return copied filtered mount options
    • cb3f358aea mount: share lazy option filtering
    • ee7ae5b7c7 mount: fix shallow copy of Options in RemoveVolatileOption and RemoveIDMapOption
    • 1facedfb21 mount: fix input mutation in readonlyMounts
    • 5ca695a441 mount: replace copyMounts with slices.Clone
  • cri: tolerate wrapped ENOTSUP during relabel (#​14211)
    • 7fd198f858 cri: tolerate wrapped ENOTSUP during relabel
  • release: don't mark 2.3 releases as latest (#​14180)
    • 147edce99f release: don't mark 2.3 releases as latest
  • cri: Backport image mount fixes 2.3 (#​14147)
    • c2c5164437 cri: only unmount image volumes when mounting fails
    • 74d0c79682 cri: enable mount manager for image mounts
  • core/unpack: fetch layers of every config-sharing manifest (#​14139)
    • 4a3a41d353 core/unpack: fetch layers of every config-sharing manifest
  • pkg/oci: mask thermal interrupt info (#​14144)
  • Update to go1.26.8 (#​14088)

Dependency Changes

This release has no dependency changes

Previous release can be found at v2.3.5

Which file should I download?
  • containerd-<VERSION>-<OS>-<ARCH>.tar.gz: ✅Recommended. Dynamically linked with glibc 2.35 (Ubuntu 22.04).
  • containerd-static-<VERSION>-<OS>-<ARCH>.tar.gz: Statically linked. Expected to be used on Linux distributions that do not use glibc >= 2.35. Not position-independent.

In addition to containerd, typically you will have to install runc
and CNI plugins from their official sites too.

See also the Getting Started documentation.

@agntcy-automation
agntcy-automation Bot requested a review from a team as a code owner September 26, 2026 00:29
@agntcy-automation agntcy-automation Bot added go Pull requests that update go code security labels Sep 26, 2026
@github-actions github-actions Bot added the size/XS Denotes a PR that changes 0-49 lines label Sep 26, 2026
@codecov

codecov Bot commented Sep 26, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@agntcy-automation
agntcy-automation Bot force-pushed the renovate/go-github.com-containerd-containerd-v2-vulnerability branch 2 times, most recently from ece8d3d to 02a26b4 Compare September 28, 2026 18:17
@lgecse
lgecse force-pushed the renovate/go-github.com-containerd-containerd-v2-vulnerability branch from 02a26b4 to feb40b3 Compare September 29, 2026 12:53
@lgecse
lgecse enabled auto-merge (squash) September 29, 2026 13:04
@lgecse
lgecse merged commit d01d08d into main Sep 29, 2026
34 checks passed
@lgecse
lgecse deleted the renovate/go-github.com-containerd-containerd-v2-vulnerability branch September 29, 2026 13:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

go Pull requests that update go code security size/XS Denotes a PR that changes 0-49 lines

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant