StackWatch

containerd

tool20 releases · 12 support lines

Support lines

LTS status and end of life
LineLatestStatusEnd of life
2.32.3.4lts30 Apr 2028
2.22.2.7ends soon6 Nov 2026
2.12.1.9eol3 Jul 2026
2.02.0.11lts1 Mar 2027
1.71.7.34ltsends soon1 Sep 2026
1.61.6.39ltseol23 Aug 2025
1.51.5.18eol28 Feb 2023
1.41.4.13eol3 Mar 2022
1.31.3.10eol4 Mar 2021
1.21.2.14eol15 Oct 2020
1.11.1.8eol23 Oct 2019
1.01.0.3eol5 Dec 2018

Releases

newest first
containerd2.3.31mo agolts
  • Fixed nil pointer dereference in NRI GetIPs during pod sandbox teardown or container exit
  • Fixed CreateContainer calls being accepted when target sandbox is not running
  • Improved error reporting from registry 403 responses by falling back to GET requests
  • Fixed Windows temp directory overrides for SYSTEM services and aligned EROFS block size across platforms
changelog ↗
containerd2.2.61mo ago
  • Fix nil pointer dereference in NRI GetIPs that could occur during pod sandbox teardown or container exit
  • Reject CreateContainer calls when the target sandbox is not running to prevent invalid operations
  • Ensure sandbox shutdown on RunPodSandbox hook failures to prevent mount leaks
  • Limit fallback to /blobs endpoint during ref resolution to prevent content store pollution
changelog ↗
containerdv2.1.82mo agosecurity
  • Fixed a security vulnerability (CVE-2026-46680)
  • Fixed handling of out-of-range USER values in OCI spec to prevent unexpected username/group lookups
  • Fixed sandbox service bugs affecting sandbox creation configuration and event publishing
  • Improved AppArmor compatibility with versions < 3.0 and added support for both "volatile" and "fsync=volatile" mount options
advisories
changelog ↗
containerd2.0.111mo agolts
  • Fixed content store pollution by limiting fallback to /blobs endpoint during image ref resolution
  • Updated Go to versions 1.26.5 and 1.25.12
changelog ↗
containerdv2.0.102mo agosecurity
  • Security patches address CVE-2026-53488 and CVE-2026-47262
  • Bounded user-database file reads in openBoundedUserFile to improve security
  • Reserved labels from image configs are no longer propagated
  • Updated runc binary to v1.3.6 and Go to 1.26.4/1.25.11
changelog ↗
containerd1.7.341mo agolts
  • Fix lost container exit events when events arrive before container info is cached
  • Update Go dependencies to latest versions
changelog ↗

← back to the digest