Summary pending.
changelog ↗containerd
tool20 releases · 12 support linesSupport lines
LTS status and end of life
| Line | Latest | Status | End of life |
|---|---|---|---|
| 2.3 | 2.3.4 | lts | 30 Apr 2028 |
| 2.2 | 2.2.7 | ends soon | 6 Nov 2026 |
| 2.1 | 2.1.9 | eol | 3 Jul 2026 |
| 2.0 | 2.0.11 | lts | 1 Mar 2027 |
| 1.7 | 1.7.34 | ltsends soon | 1 Sep 2026 |
| 1.6 | 1.6.39 | ltseol | 23 Aug 2025 |
| 1.5 | 1.5.18 | eol | 28 Feb 2023 |
| 1.4 | 1.4.13 | eol | 3 Mar 2022 |
| 1.3 | 1.3.10 | eol | 4 Mar 2021 |
| 1.2 | 1.2.14 | eol | 15 Oct 2020 |
| 1.1 | 1.1.8 | eol | 23 Oct 2019 |
| 1.0 | 1.0.3 | eol | 5 Dec 2018 |
Releases
newest first
Summary pending.
changelog ↗- Fixed nil pointer dereference in NRI GetIPs during pod sandbox teardown or container exit
- Fixed CreateContainer calls being accepted when target sandbox is not running
- Improved error reporting from registry 403 responses by falling back to GET requests
- Fixed Windows temp directory overrides for SYSTEM services and aligned EROFS block size across platforms
- Security patches address five CVEs (CVE-2026-50195, CVE-2026-53488, CVE-2026-53492, CVE-2026-53489, CVE-2026-47262)
- Fixed data race when reading shim logs on Windows
- Fixed container startup failures caused by concurrent task RPC timeouts during slow container creation
- Improved image distribution with retry logic for transient network errors
Summary pending.
changelog ↗- Fix nil pointer dereference in NRI GetIPs that could occur during pod sandbox teardown or container exit
- Reject CreateContainer calls when the target sandbox is not running to prevent invalid operations
- Ensure sandbox shutdown on RunPodSandbox hook failures to prevent mount leaks
- Limit fallback to /blobs endpoint during ref resolution to prevent content store pollution
- Security patches for five CVEs (CVE-2026-50195, CVE-2026-53488, CVE-2026-53492, CVE-2026-53489, CVE-2026-47262)
- CRI checkpoint restore improvements including filtering CDI annotations and handling unexpected archive content
- User-database file read bounds checking in openUserFile
- Reserved labels no longer propagated from image configs
- Security patches address five CVEs (CVE-2026-50195, CVE-2026-53488, CVE-2026-53492, CVE-2026-53489, CVE-2026-47262)
- CRI checkpoint restore is now more robust and filters CDI annotations correctly
- User database file reads are bounded to prevent resource exhaustion
- Reserved labels from image configs are no longer propagated
- Fixed a security vulnerability (CVE-2026-46680)
- Fixed handling of out-of-range USER values in OCI spec to prevent unexpected username/group lookups
- Fixed sandbox service bugs affecting sandbox creation configuration and event publishing
- Improved AppArmor compatibility with versions < 3.0 and added support for both "volatile" and "fsync=volatile" mount options
advisories
- Fixed content store pollution by limiting fallback to /blobs endpoint during image ref resolution
- Updated Go to versions 1.26.5 and 1.25.12
- Security patches address CVE-2026-53488 and CVE-2026-47262
- Bounded user-database file reads in openBoundedUserFile to improve security
- Reserved labels from image configs are no longer propagated
- Updated runc binary to v1.3.6 and Go to 1.26.4/1.25.11
advisories
- Fix lost container exit events when events arrive before container info is cached
- Update Go dependencies to latest versions
- Security patches for CVE-2026-53488 and CVE-2026-47262 in containerd
- Security patch for CVE-2026-34986 in go-jose dependency
- Updated runc binary to v1.3.6
- Fixed user-database file reads and image config label propagation
No changelog text published for this release.
changelog ↗No changelog text published for this release.
changelog ↗No changelog text published for this release.
changelog ↗No changelog text published for this release.
changelog ↗No changelog text published for this release.
changelog ↗No changelog text published for this release.
changelog ↗No changelog text published for this release.
changelog ↗