#1149966 containerd: CVE-2026-53493

Package:
src:containerd
Source:
src:containerd
Submitter:
Salvatore Bonaccorso
Date:
2026-10-04 23:39:05 UTC
Severity:
normal
Tags:
#1149966#5
Date:
2026-10-04 19:44:30 UTC
From:
To:
Hi,

The following vulnerability was published for containerd.

CVE-2026-53493[0]:
| containerd is an open-source container runtime. Prior to versions
| 1.7.36, 2.0.13, 2.2.9, 2.3.6, and 2.4.1, a crafted OCI index graph
| can force very high CPU/memory usage during PullImage (before
| container start), causing long ContainerCreating stalls and, at
| larger sizes, node/runtime instability. Versions 1.7.36, 2.0.13,
| 2.2.9, 2.3.6, and 2.4.1 fix the issue.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-53493
https://www.cve.org/CVERecord?id=CVE-2026-53493
[1] https://github.com/containerd/containerd/security/advisories/GHSA-pg57-6jwg-q645

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1149966#8
Date:
2026-10-04 21:19:00 UTC
From:
To:
Hello,

Bug #1149966 in containerd reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/go-team/packages/containerd/-/commit/28106a29f866cc8c463117e01546c3e89de892a7
Add patch 0009-Bound-image-handlers-concurrency-and-references-CVE-.patch
backporting upstream commits 94e83c14c8 and 4f5f32636d to bound Dispatch
concurrency and Walk references to 10,000 against malicious OCI index graphs.
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1149966

#1149966#13
Date:
2026-10-04 21:26:15 UTC
From:
To:
Hello,

Bug #1149966 in containerd reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/go-team/packages/containerd/-/commit/4ef1caddef9b06c74cc477e0238b124b9a9f865f
Add patch 0012-Bound-image-handlers-concurrency-and-references-CVE-2026-53493.patch
backporting upstream commits 94e83c14c8 and 4f5f32636d to bound Dispatch
concurrency and Walk references to 10,000 against malicious OCI index graphs.
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1149966

#1149966#16
Date:
2026-10-04 21:53:18 UTC
From:
To:
Hello,

Bug #1149966 in containerd reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/go-team/packages/containerd/-/commit/4ef1caddef9b06c74cc477e0238b124b9a9f865f
Add patch 0012-Bound-image-handlers-concurrency-and-references-CVE-2026-53493.patch
backporting upstream commits 94e83c14c8 and 4f5f32636d to bound Dispatch
concurrency and Walk references to 10,000 against malicious OCI index graphs.
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1149966

#1149966#21
Date:
2026-10-04 23:38:34 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
containerd, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1149966@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Reinhard Tartler <siretart@tauware.de> (supplier of updated containerd package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sun, 04 Oct 2026 18:51:32 -0400
Source: containerd
Architecture: source
Version: 2.1.9+ds1-5
Distribution: unstable
Urgency: medium
Maintainer: Debian Go Packaging Team <team+pkg-go@tracker.debian.org>
Changed-By: Reinhard Tartler <siretart@tauware.de>
Closes: 1149966
Changes:
 containerd (2.1.9+ds1-5) unstable; urgency=medium
 .
   * Backport fix for CVE-2026-53493 (Closes: #1149966)
   * debian/patches/0008: Add Forwarded: not-needed header
Checksums-Sha1:
 20994266220eb474316a82a7058190cf138d7349 5720 containerd_2.1.9+ds1-5.dsc
 0a66737924998908ed8db45044cc151c65220816 802868 containerd_2.1.9+ds1-5.debian.tar.xz
Checksums-Sha256:
 3365c89e4fddaab26fc80586b8542b0c54d0d1ea946bc91e8c150199d6acc55b 5720 containerd_2.1.9+ds1-5.dsc
 e80e372edecb9c9ed54aa5cb20edaa1ebdc5e2723b536ca72ddf5fc309b918f2 802868 containerd_2.1.9+ds1-5.debian.tar.xz
Files:
 33b9d4a5b7cf02afc2725f437566fcca 5720 admin optional containerd_2.1.9+ds1-5.dsc
 321d342ded0bad68108ebea6d5b7e5c9 802868 admin optional containerd_2.1.9+ds1-5.debian.tar.xz
-----BEGIN PGP SIGNATURE-----

iQJIBAEBCgAyFiEEMN59F2OrlFLH4IJQSadpd5QoJssFAmrC2KgUHHNpcmV0YXJ0
QHRhdXdhcmUuZGUACgkQSadpd5QoJsuZ4RAAgi1+EENG1I2EVqtgdwvVOVTwfXEN
Wf/EWq2L2dyVH8WU2HGMxhQ8EYHy41LXQ+tZdx+uCNb7GFaFQbcWFHqmD/U6CxKb
4RvKIp1gfJr04sGoqXYkgj3OL3PSJ2k+8T5hSggYdvHvHIdmwHHlQZ1N0ygEcxqj
JyMAefZX1m/r6sKRsYcV96zY+V1nk0b53aDc31Yw8Ls16IHptOuQJSKs5K6yLeHu
vu7mnTuanGP/pRYGem+KXyjPP2RDegvgKbmbNu5aj7XtO0LN7lLysRrxGfzlZb1w
JtHl69r7gSG3DS9faeW9/aB8RwxanwXLvnXiiOZ09yK1amjZ4jgp9fYzU9GbV8Op
lioL80TTuxczJx0dQ2nHwT09PS1wBLde5zwMSpr+CtGK3d07pfwDKAGczT2zCPLC
qwfn3tkoYn0euw6BC2WX44bjBpFHfC61uGVVHJpMHjotugGCeH2RVg/WBB99hE1L
KtfuckhE/d6s1qdf99PhcCZ1lSXxtqXB4SpxK/HcTTJF7FlHd/3/N/8xcpNqokab
gPDrRXLtC63OEBJtZfvace4RzgsWaSfEVkXbYuNkOPoElYelI1aosHnTBnRw+HXO
7wExXUFL91hh9TFtBKmxLwIfn5RUyWH9KePAjATNtnZKLysL05Ho5ilNoJK7F4PN
mW5h+Cn6dZ5dBtA=
=tnFK
-----END PGP SIGNATURE-----