What containerd/containerd shipped
Written by FoxPlug from public releases; not affiliated with Containerd. An automatic summary of the public release, pull request and commit data of github.com/containerd/containerd. Containerd did not write it and does not use or endorse FoxPlug. Every line links to the public change it describes.
Get a weekly update like this for your product, free
Week of September 21, 2026
What shipped
- containerd 1.7.36 released with security patch CVE-2026-53493 and various fixes including image storage improvements. Release
- containerd 2.4.1 released with security patch CVE-2026-53493 and CRI fixes including task leak prevention during failed container starts. Release
- containerd 2.2.9 released with security patch CVE-2026-53493 and CRI fix for SELinux relabeling failures. Release
- containerd 2.3.6 released with security patch CVE-2026-53493 and CRI fix for SELinux relabeling failures. Release
- containerd 2.0.13 released with security patch CVE-2026-53493 and image storage improvements. Release
- runc updated to v1.5.2 with workaround for Linux kernel cgroup v2 bug and regression fixes including HOME environment variable handling. Pull request #14231
- Fixed task leak in CRI when StartContainer cleanup fails to delete task, preventing container removal. Pull request #14218
- Fixed ctr images export command to preserve arguments following dash separator. Pull request #14217
- Fixed flag parsing issues in ctr run, containers create, tasks exec, and oci-hook commands. Pull request #14209
- Applied hardening to filter ID-mapping labels from image annotations during unpack to prevent snapshotter privilege escalation. Pull request #13855
Why it matters
This week delivered five patch releases across active containerd versions addressing a security vulnerability and several resource leaks and command-line parsing bugs. These fixes improve reliability in container runtime operations and address issues affecting CRI, image storage, and command-line tool behavior.
Changelog entry
- runc binary updated to v1.5.2 with Linux kernel cgroup v2 bug workaround and regression fixes Pull request #14231
- Add conditional GitHub Actions to skip certain CI checks for private security patch validation forks Pull request #14232
- Fix resource leak when StartContainer cleanup fails to delete task in CRI Pull request #14218
- Preserve arguments after dash in ctr images export command Pull request #14217
- Fix flag parsing in ctr run, containers create, tasks exec, and oci-hook Pull request #14209
- Use stable service name containerd-shim-runc-v2 in OpenTelemetry instrumentation Pull request #14201
- Tolerate wrapped ENOTSUP errors during SELinux relabeling on unsupported filesystems in CRI Pull request #14207
- Filter ID-mapping labels from image annotations during unpack to prevent privilege escalation Pull request #13855
containerd patch releases: 1.7.36, 2.0.13, 2.2.9, 2.3.6, 2.4.1. Security fix CVE-2026-53493 and CRI/image storage improvements.
We released patch updates across containerd versions 1.7.36, 2.0.13, 2.2.9, 2.3.6, and 2.4.1 this week. These releases address security concern CVE-2026-53493 alongside important fixes for task leaks during failed container starts, SELinux relabeling failures, image layer fetching, and command-line argument parsing. runc was also updated to v1.5.2 with a kernel bug workaround.
Week of September 14, 2026
What shipped
- containerd 2.4.0 released as a regular non-LTS release with a shorter support window for users who want to adopt new features sooner. Release
- containerd API 1.12.0 released, aligning with containerd 2.4 and including media type in content create events and UpdateSandbox RPC for sandbox controller updates. Release
- Fixed content upload failures when retrying fetch content after reaching EOF in release/2.4 branch. Pull request #14197
- Fixed bug in ctr subcommands where comma-separated flag values were incorrectly split in release/2.4 branch. Pull request #14188
- Masked /proc/interrupts and /sys/devices/system/cpu thermal throttle inside Linux containers by default across release/1.7, /2.0, /2.2, and /2.3 branches. Pull request #14184
- Updated fxamacker/cbor dependency to v2.9.4 which fixes various potential panics. Pull request #14174
- Removed deprecated CRI and tracing configuration options including
enable_cdi,bin_dir, and OTLP endpoint parameters. Pull request #14166 - Fixed urfave/cli/v3 migration issue where child commands no longer inherited DisableSliceFlagSeparator from root command. Pull request #14185
- Fixed unpacking to fetch layers of every config-sharing manifest in an index to support manifests with identical configs but different compression. Pull request #14142
Why it matters
containerd 2.4.0 is now available as a regular release focused on new features following the 2.3 LTS. The API 1.12.0 release adds sandbox controller updates and media type tracking. Multiple bug fixes address registry uploads, CLI flag handling, and container isolation.
Changelog entry
- containerd 2.4.0 released Release
- containerd API 1.12.0 released Release
- Reverted closing fetch readers at EOF to restore registry-cache upload retries Pull request #14194
- Fixed ctr subcommands to disable slice flag separator on urfave/cli/v3 Pull request #14185
- Masked /proc/interrupts and /sys/devices/system/cpu thermal throttle in containers Pull request #14184
- Updated fxamacker/cbor to v2.9.4 to fix potential panics Pull request #14174
- Removed deprecated
enable_cdi,bin_dir, and OTLP tracing configuration options Pull request #14166 - Fixed unpacking to fetch layers from config-sharing manifests in indices Pull request #14142
containerd 2.4.0 and API 1.12.0 are now available. This non-LTS release includes bug fixes for registry uploads, CLI flags, and container isolation. See release notes for full details.
containerd 2.4.0 and API 1.12.0 releases are now available. As a regular non-LTS release, 2.4.0 introduces new features with a shorter support window for early adopters. Key fixes include content upload retry handling, CLI flag parsing in subcommands, and default masking of thermal interrupt information in containers. The API release adds sandbox controller update propagation and media type tracking in content events.