- Package:
- src:containerd
- Source:
- src:containerd
- Submitter:
- Salvatore Bonaccorso
- Date:
- 2026-10-04 23:39:05 UTC
- Severity:
- normal
- Tags:
Hi, The following vulnerability was published for containerd. CVE-2026-53493[0]: | containerd is an open-source container runtime. Prior to versions | 1.7.36, 2.0.13, 2.2.9, 2.3.6, and 2.4.1, a crafted OCI index graph | can force very high CPU/memory usage during PullImage (before | container start), causing long ContainerCreating stalls and, at | larger sizes, node/runtime instability. Versions 1.7.36, 2.0.13, | 2.2.9, 2.3.6, and 2.4.1 fix the issue. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-53493 https://www.cve.org/CVERecord?id=CVE-2026-53493 [1] https://github.com/containerd/containerd/security/advisories/GHSA-pg57-6jwg-q645 Please adjust the affected versions in the BTS as needed. Regards, Salvatore
Hello, Bug #1149966 in containerd reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/go-team/packages/containerd/-/commit/28106a29f866cc8c463117e01546c3e89de892a7 Add patch 0009-Bound-image-handlers-concurrency-and-references-CVE-.patch backporting upstream commits 94e83c14c8 and 4f5f32636d to bound Dispatch concurrency and Walk references to 10,000 against malicious OCI index graphs. ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1149966
Hello, Bug #1149966 in containerd reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/go-team/packages/containerd/-/commit/4ef1caddef9b06c74cc477e0238b124b9a9f865f Add patch 0012-Bound-image-handlers-concurrency-and-references-CVE-2026-53493.patch backporting upstream commits 94e83c14c8 and 4f5f32636d to bound Dispatch concurrency and Walk references to 10,000 against malicious OCI index graphs. ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1149966
Hello, Bug #1149966 in containerd reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/go-team/packages/containerd/-/commit/4ef1caddef9b06c74cc477e0238b124b9a9f865f Add patch 0012-Bound-image-handlers-concurrency-and-references-CVE-2026-53493.patch backporting upstream commits 94e83c14c8 and 4f5f32636d to bound Dispatch concurrency and Walk references to 10,000 against malicious OCI index graphs. ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1149966
We believe that the bug you reported is fixed in the latest version of containerd, which is due to be installed in the Debian FTP archive. A summary of the changes between this version and the previous one is attached. Thank you for reporting the bug, which will now be closed. If you have further comments please address them to 1149966@bugs.debian.org, and the maintainer will reopen the bug report if appropriate. Debian distribution maintenance software pp. Reinhard Tartler <siretart@tauware.de> (supplier of updated containerd package) (This message was generated automatically at their request; if you believe that there is a problem with it please contact the archive administrators by mailing ftpmaster@ftp-master.debian.org) Format: 1.8 Date: Sun, 04 Oct 2026 18:51:32 -0400 Source: containerd Architecture: source Version: 2.1.9+ds1-5 Distribution: unstable Urgency: medium Maintainer: Debian Go Packaging Team <team+pkg-go@tracker.debian.org> Changed-By: Reinhard Tartler <siretart@tauware.de> Closes: 1149966 Changes: containerd (2.1.9+ds1-5) unstable; urgency=medium . * Backport fix for CVE-2026-53493 (Closes: #1149966) * debian/patches/0008: Add Forwarded: not-needed header Checksums-Sha1: 20994266220eb474316a82a7058190cf138d7349 5720 containerd_2.1.9+ds1-5.dsc 0a66737924998908ed8db45044cc151c65220816 802868 containerd_2.1.9+ds1-5.debian.tar.xz Checksums-Sha256: 3365c89e4fddaab26fc80586b8542b0c54d0d1ea946bc91e8c150199d6acc55b 5720 containerd_2.1.9+ds1-5.dsc e80e372edecb9c9ed54aa5cb20edaa1ebdc5e2723b536ca72ddf5fc309b918f2 802868 containerd_2.1.9+ds1-5.debian.tar.xz Files: 33b9d4a5b7cf02afc2725f437566fcca 5720 admin optional containerd_2.1.9+ds1-5.dsc 321d342ded0bad68108ebea6d5b7e5c9 802868 admin optional containerd_2.1.9+ds1-5.debian.tar.xz -----BEGIN PGP SIGNATURE----- iQJIBAEBCgAyFiEEMN59F2OrlFLH4IJQSadpd5QoJssFAmrC2KgUHHNpcmV0YXJ0 QHRhdXdhcmUuZGUACgkQSadpd5QoJsuZ4RAAgi1+EENG1I2EVqtgdwvVOVTwfXEN Wf/EWq2L2dyVH8WU2HGMxhQ8EYHy41LXQ+tZdx+uCNb7GFaFQbcWFHqmD/U6CxKb 4RvKIp1gfJr04sGoqXYkgj3OL3PSJ2k+8T5hSggYdvHvHIdmwHHlQZ1N0ygEcxqj JyMAefZX1m/r6sKRsYcV96zY+V1nk0b53aDc31Yw8Ls16IHptOuQJSKs5K6yLeHu vu7mnTuanGP/pRYGem+KXyjPP2RDegvgKbmbNu5aj7XtO0LN7lLysRrxGfzlZb1w JtHl69r7gSG3DS9faeW9/aB8RwxanwXLvnXiiOZ09yK1amjZ4jgp9fYzU9GbV8Op lioL80TTuxczJx0dQ2nHwT09PS1wBLde5zwMSpr+CtGK3d07pfwDKAGczT2zCPLC qwfn3tkoYn0euw6BC2WX44bjBpFHfC61uGVVHJpMHjotugGCeH2RVg/WBB99hE1L KtfuckhE/d6s1qdf99PhcCZ1lSXxtqXB4SpxK/HcTTJF7FlHd/3/N/8xcpNqokab gPDrRXLtC63OEBJtZfvace4RzgsWaSfEVkXbYuNkOPoElYelI1aosHnTBnRw+HXO 7wExXUFL91hh9TFtBKmxLwIfn5RUyWH9KePAjATNtnZKLysL05Ho5ilNoJK7F4PN mW5h+Cn6dZ5dBtA= =tnFK -----END PGP SIGNATURE-----