#1148180 containerd: CVE-2026-53495

Package:
src:containerd
Source:
src:containerd
Submitter:
Salvatore Bonaccorso
Date:
2026-10-03 14:25:04 UTC
Severity:
normal
Tags:
#1148180#5
Date:
2026-09-17 20:49:10 UTC
From:
To:
Hi,

The following vulnerability was published for containerd.

CVE-2026-53495[0]:
| containerd is an open-source container runtime. Prior to 1.7.35,
| 2.0.12, 2.2.8, and 2.3.5, containerd on Linux with the CRI plugin
| enabled can indefinitely block the drainExecSyncIO goroutine in
| internal/cri/server/container_execsync.go when CRI ExecSync is used
| by exec probes or lifecycle hooks that launch long-lived background
| child processes retaining standard input and output pipes. The input
| and output drain phase has no default timeout and did not stop when
| the request context was canceled, so repeated ExecSync invocations
| can accumulate blocked goroutines and host memory. The resulting
| resource exhaustion can cause the OOM killer to terminate
| containerd, leaving the container runtime unavailable until restart.
| Deployments not using containerd's CRI implementation and containers
| not running on Linux are not affected. This issue is fixed in
| versions 1.7.35, 2.0.12, 2.2.8, and 2.3.5.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-53495
https://www.cve.org/CVERecord?id=CVE-2026-53495
[1] https://github.com/containerd/containerd/security/advisories/GHSA-7jxh-36q5-gcqv

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1148180#8
Date:
2026-10-02 21:12:36 UTC
From:
To:
Hello,

Bug #1148180 in containerd reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/go-team/packages/containerd/-/commit/5e1146e42268a0edd72fa77d560e6845c92557ab
------------------------------------------------------------------------
d/patches: backport upstream fix for CVE-2026-53495 (Closes: #1148180)
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1148180

#1148180#13
Date:
2026-10-02 21:24:02 UTC
From:
To:
Hello,

Bug #1148180 in containerd reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/go-team/packages/containerd/-/commit/a54829d4a4f22a6d629dd679d3522f4dba535342
------------------------------------------------------------------------
d/patches: backport upstream fix for CVE-2026-53495 (Closes: #1148180)
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1148180

#1148180#16
Date:
2026-10-02 21:31:12 UTC
From:
To:
Hello,

Bug #1148180 in containerd reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/go-team/packages/containerd/-/commit/a54829d4a4f22a6d629dd679d3522f4dba535342
------------------------------------------------------------------------
d/patches: backport upstream fix for CVE-2026-53495 (Closes: #1148180)
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1148180

#1148180#21
Date:
2026-10-03 14:24:17 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
containerd, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1148180@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Reinhard Tartler <siretart@tauware.de> (supplier of updated containerd package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Fri, 02 Oct 2026 17:38:11 -0400
Source: containerd
Architecture: source
Version: 2.1.9+ds1-4
Distribution: unstable
Urgency: medium
Maintainer: Debian Go Packaging Team <team+pkg-go@tracker.debian.org>
Changed-By: Reinhard Tartler <siretart@tauware.de>
Closes: 1148180
Changes:
 containerd (2.1.9+ds1-4) unstable; urgency=medium
 .
   [ Marcos Talau ]
   * Enable Salsa CI using default template
 .
   [ Reinhard Tartler ]
   * restore original salsa pipeline definition
   * debian/lrc.config: ignore false-positive dual-license discrepancies
   * d/patches: backport upstream fix for CVE-2026-53495 (Closes: #1148180)
Checksums-Sha1:
 6d464fe8a509005b2c35b52df0734106aa51f533 5720 containerd_2.1.9+ds1-4.dsc
 44127fe502b6a33c5dda0f0642b3c57d19c74584 798680 containerd_2.1.9+ds1-4.debian.tar.xz
Checksums-Sha256:
 b798ca4bccf4e0522163e26619b3ba42bd7e92048e2f1f01a2d53c49ec27296f 5720 containerd_2.1.9+ds1-4.dsc
 462132e98e9794b86aa9a9b8e883e6f0ca0bae1a6ebda5b1f8232215aab85c0b 798680 containerd_2.1.9+ds1-4.debian.tar.xz
Files:
 94ae084d9f4cbfba7411e90dbb3f1cd4 5720 admin optional containerd_2.1.9+ds1-4.dsc
 e70c46646b4b1a9ed15e79f6016c8f40 798680 admin optional containerd_2.1.9+ds1-4.debian.tar.xz
-----BEGIN PGP SIGNATURE-----

iQJIBAEBCgAyFiEEMN59F2OrlFLH4IJQSadpd5QoJssFAmrBC8QUHHNpcmV0YXJ0
QHRhdXdhcmUuZGUACgkQSadpd5QoJsspmBAA0JfWhHA7x1SpL1ZBp1Hbc39Eo6Ji
jbHhwSajOR7PPkq8H3HsCasA8vAxuDonugV8HeYyYpsxaKPMmEOr/EfJe/pVJW9E
H1x7y63ni67mijo7LZ826ccIT1PQ0tGtber+m+jXEXxEQucP653fBsyTN0me19JC
Gz/Oj89U4vzFH7RddPfS50AfcWWnoFm7bhmL2uS80k09DjbLL+raK8I5rQ6zJXdB
0NuR4satkgGO98CT4xbipJXxE7k3hkcYPZPIsyQS5lH5IZ8rjA0UtWnDL6yrRn8Q
BUGZMCC2O28/tnl74icbN2YNpGaQSoxxrgNdO+Py0my38XnurzMETW0KFG/Pg9dd
cUtQB0FhDRdfB2ZQPmXChWJ6L9vtlhblBORPqIW+KslYyvoIBtc24Nbvcm42A/oO
rqH0+ntaX0meP4whBLGQzdJP+a2Tgy+n2Cs7REa2JrAaj64sRaNGmtjay2NJoCyr
9oqoHEdvCt032/ukBBJa9kPy4bm0ur2nyG1ZHNgtFZc/AnCYJrvYQMEVp/xHWVoq
rKnLMKfRA9jzYxk0wralf1mi4CM8Wspm50ghK9+jbRUDNawbVJ2D+9X75lZz9S0o
vmikP8M8Ft0ckBNhFefJXprlqIUnIBkRkNPteTazr8ZyPBmXKhzTQsNemO9xvcLd
TQfNWTARRhmJWjw=
=s2I2
-----END PGP SIGNATURE-----