- Package:
- src:containerd
- Source:
- src:containerd
- Submitter:
- Salvatore Bonaccorso
- Date:
- 2026-10-03 14:25:04 UTC
- Severity:
- normal
- Tags:
Hi, The following vulnerability was published for containerd. CVE-2026-53495[0]: | containerd is an open-source container runtime. Prior to 1.7.35, | 2.0.12, 2.2.8, and 2.3.5, containerd on Linux with the CRI plugin | enabled can indefinitely block the drainExecSyncIO goroutine in | internal/cri/server/container_execsync.go when CRI ExecSync is used | by exec probes or lifecycle hooks that launch long-lived background | child processes retaining standard input and output pipes. The input | and output drain phase has no default timeout and did not stop when | the request context was canceled, so repeated ExecSync invocations | can accumulate blocked goroutines and host memory. The resulting | resource exhaustion can cause the OOM killer to terminate | containerd, leaving the container runtime unavailable until restart. | Deployments not using containerd's CRI implementation and containers | not running on Linux are not affected. This issue is fixed in | versions 1.7.35, 2.0.12, 2.2.8, and 2.3.5. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-53495 https://www.cve.org/CVERecord?id=CVE-2026-53495 [1] https://github.com/containerd/containerd/security/advisories/GHSA-7jxh-36q5-gcqv Please adjust the affected versions in the BTS as needed. Regards, Salvatore
Hello, Bug #1148180 in containerd reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/go-team/packages/containerd/-/commit/5e1146e42268a0edd72fa77d560e6845c92557ab ------------------------------------------------------------------------ d/patches: backport upstream fix for CVE-2026-53495 (Closes: #1148180) ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1148180
Hello, Bug #1148180 in containerd reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/go-team/packages/containerd/-/commit/a54829d4a4f22a6d629dd679d3522f4dba535342 ------------------------------------------------------------------------ d/patches: backport upstream fix for CVE-2026-53495 (Closes: #1148180) ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1148180
Hello, Bug #1148180 in containerd reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/go-team/packages/containerd/-/commit/a54829d4a4f22a6d629dd679d3522f4dba535342 ------------------------------------------------------------------------ d/patches: backport upstream fix for CVE-2026-53495 (Closes: #1148180) ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1148180
We believe that the bug you reported is fixed in the latest version of containerd, which is due to be installed in the Debian FTP archive. A summary of the changes between this version and the previous one is attached. Thank you for reporting the bug, which will now be closed. If you have further comments please address them to 1148180@bugs.debian.org, and the maintainer will reopen the bug report if appropriate. Debian distribution maintenance software pp. Reinhard Tartler <siretart@tauware.de> (supplier of updated containerd package) (This message was generated automatically at their request; if you believe that there is a problem with it please contact the archive administrators by mailing ftpmaster@ftp-master.debian.org) Format: 1.8 Date: Fri, 02 Oct 2026 17:38:11 -0400 Source: containerd Architecture: source Version: 2.1.9+ds1-4 Distribution: unstable Urgency: medium Maintainer: Debian Go Packaging Team <team+pkg-go@tracker.debian.org> Changed-By: Reinhard Tartler <siretart@tauware.de> Closes: 1148180 Changes: containerd (2.1.9+ds1-4) unstable; urgency=medium . [ Marcos Talau ] * Enable Salsa CI using default template . [ Reinhard Tartler ] * restore original salsa pipeline definition * debian/lrc.config: ignore false-positive dual-license discrepancies * d/patches: backport upstream fix for CVE-2026-53495 (Closes: #1148180) Checksums-Sha1: 6d464fe8a509005b2c35b52df0734106aa51f533 5720 containerd_2.1.9+ds1-4.dsc 44127fe502b6a33c5dda0f0642b3c57d19c74584 798680 containerd_2.1.9+ds1-4.debian.tar.xz Checksums-Sha256: b798ca4bccf4e0522163e26619b3ba42bd7e92048e2f1f01a2d53c49ec27296f 5720 containerd_2.1.9+ds1-4.dsc 462132e98e9794b86aa9a9b8e883e6f0ca0bae1a6ebda5b1f8232215aab85c0b 798680 containerd_2.1.9+ds1-4.debian.tar.xz Files: 94ae084d9f4cbfba7411e90dbb3f1cd4 5720 admin optional containerd_2.1.9+ds1-4.dsc e70c46646b4b1a9ed15e79f6016c8f40 798680 admin optional containerd_2.1.9+ds1-4.debian.tar.xz -----BEGIN PGP SIGNATURE----- iQJIBAEBCgAyFiEEMN59F2OrlFLH4IJQSadpd5QoJssFAmrBC8QUHHNpcmV0YXJ0 QHRhdXdhcmUuZGUACgkQSadpd5QoJsspmBAA0JfWhHA7x1SpL1ZBp1Hbc39Eo6Ji jbHhwSajOR7PPkq8H3HsCasA8vAxuDonugV8HeYyYpsxaKPMmEOr/EfJe/pVJW9E H1x7y63ni67mijo7LZ826ccIT1PQ0tGtber+m+jXEXxEQucP653fBsyTN0me19JC Gz/Oj89U4vzFH7RddPfS50AfcWWnoFm7bhmL2uS80k09DjbLL+raK8I5rQ6zJXdB 0NuR4satkgGO98CT4xbipJXxE7k3hkcYPZPIsyQS5lH5IZ8rjA0UtWnDL6yrRn8Q BUGZMCC2O28/tnl74icbN2YNpGaQSoxxrgNdO+Py0my38XnurzMETW0KFG/Pg9dd cUtQB0FhDRdfB2ZQPmXChWJ6L9vtlhblBORPqIW+KslYyvoIBtc24Nbvcm42A/oO rqH0+ntaX0meP4whBLGQzdJP+a2Tgy+n2Cs7REa2JrAaj64sRaNGmtjay2NJoCyr 9oqoHEdvCt032/ukBBJa9kPy4bm0ur2nyG1ZHNgtFZc/AnCYJrvYQMEVp/xHWVoq rKnLMKfRA9jzYxk0wralf1mi4CM8Wspm50ghK9+jbRUDNawbVJ2D+9X75lZz9S0o vmikP8M8Ft0ckBNhFefJXprlqIUnIBkRkNPteTazr8ZyPBmXKhzTQsNemO9xvcLd TQfNWTARRhmJWjw= =s2I2 -----END PGP SIGNATURE-----