Skip to content

chore(deps): update module github.com/containerd/containerd/v2 to v2.2.9 [security] - #374

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/go-github.com-containerd-containerd-v2-vulnerability
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/go-github.com-containerd-containerd-v2-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Sep 25, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
github.com/containerd/containerd/v2 v2.2.8 → v2.2.9 age confidence

Containerd has image-pull DoS via crafted OCI index graph amplification

CVE-2026-53493 / GHSA-pg57-6jwg-q645

More information

Details

Impact

A vulnerability exists in containerd's image pull handlers where a crafted OCI image index containing deeply nested or heavily fanned-out descriptor graphs can cause unbounded CPU and memory consumption. During the PullImage operation, the recursive traversal and processing of child descriptors lack sufficient depth and breadth limits, and fail to adequately deduplicate identical descriptors. This unbounded traversal leads to excessive resource allocation.

Consequently, pulling a malicious image reference can result in prolonged stalls during container creation and significant resource pressure on the host system. This issue occurs entirely during the image pull phase, prior to any container execution.

Patches

This bug has been fixed in containerd 2.4.1, 2.3.6, 2.2.9, 2.0.13, and 1.7.36. Users should update to these versions to resolve the issue.

Workarounds

There are no known workarounds for this issue. Users are advised to only pull trusted images from known registries until the patch can be applied.

Credits

The containerd project would like to thank Jakub Ciolek at ElevenLabs and @​jlgore who independently discovered and responsibly disclosed this issue in accordance with the containerd security policy.

For more information

If you have any questions or comments about this advisory:

To report a security issue in containerd:

Severity

  • CVSS Score: 6.9 / 10 (Medium)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Release Notes

containerd/containerd (github.com/containerd/containerd/v2)

v2.2.9: containerd 2.2.9

Compare Source

Welcome to the v2.2.9 release of containerd!

The ninth patch release for containerd 2.2 contains various fixes
and updates including a security patch.

Security Updates
Highlights
Container Runtime Interface (CRI)
  • Fix bug where container creation failed when SELinux relabeling was unsupported by the filesystem (#​14210)
  • Enable mount manager for image mounts in CRI (#​14148)
Image Storage
  • Ensure all layers are fetched when multiple manifests in an index share a config descriptor (#​14140)
Runtime
  • Mask /proc/interrupts and CPU thermal throttle sysfs paths in Linux containers by default (#​14182)

Please try out the release binaries and report any issues at
https://github.com/containerd/containerd/issues.

Contributors
  • Samuel Karp
  • Chris Henzie
  • Maksym Pavlenko
  • Wei Fu
  • Gao Xiang
  • Nan Liu
Changes
13 commits

  • 60acf78bc5 Prepare release notes for v2.2.9
  • 253f9cc140 Merge commit from fork
  • 053c0cc412 Bound Walk references
  • efd11fc9c2 Bound Dispatch concurrency and references
  • cri: tolerate wrapped ENOTSUP during relabel (#​14210)
    • 39d0dd4b43 cri: tolerate wrapped ENOTSUP during relabel
  • pkg/oci: mask thermal interrupt info (#​14182)
  • core/unpack: fetch layers of every config-sharing manifest (#​14140)
    • 9e1ae6a9e9 core/unpack: fetch layers of every config-sharing manifest
  • cri: Backport image mount fixes 2.2 (#​14148)
    • 2cdf8d80cc cri: only unmount image volumes when mounting fails
    • 2e1dcc5da0 cri: enable mount manager for image mounts

Dependency Changes

This release has no dependency changes

Previous release can be found at v2.2.8

Which file should I download?
  • containerd-<VERSION>-<OS>-<ARCH>.tar.gz: ✅Recommended. Dynamically linked with glibc 2.35 (Ubuntu 22.04).
  • containerd-static-<VERSION>-<OS>-<ARCH>.tar.gz: Statically linked. Expected to be used on Linux distributions that do not use glibc >= 2.35. Not position-independent.

In addition to containerd, typically you will have to install runc
and CNI plugins from their official sites too.

See also the Getting Started documentation.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot requested a review from a team as a code owner September 25, 2026 23:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant