containerd
v2.3.5Kubernetes CoreSep 4, 2026
A maintenance release with two disclosed security fixes, reliability and compatibility corrections, and dependency updates. No migration requirement is stated.
Action needed (1)
securityThe containerd fix for CVE-2026-53495
The
containerdrelease includes a fix for CVE-2026-53495, also tracked as GHSA-rp3h-jf77-q9p4.
All 14 other recorded changesfixes 7 · value changes 7
fixes (7)
- Fix data races and a deadlock in the byte stream helpers
- snapshots/erofs: advertise the erofs OS feature from the snapshotter plugin
- pkg/tracing: handle error and typed-nil Stringer attributes
- pkg/oci: resolve rootfs symlinks for user lookup
- ensure that the final config version is the higest in the config list
- fix(runtime): apply load timeout to load shim
- Fix WS2022 compat on hosts past the latest LTSC
value changes (7)
- cri: cancel ExecSync IO drain on context cancellation
- archive: skip redundant opaque whiteout walks
- update runc to v1.5.1
- vendor: github.com/containerd/platforms v1.0.0-rc.5
- docker fetcher: strip sensitive headers on descriptor URLs
- update runhcs to v0.15.0-rc.4
- Add more context to the shim delete error
Add containerd to your stack
A weekly email arrives when a release needs action. Like the security patches in this release.