A maintenance release with a disclosed security fix, a narrower default socket policy, expanded compatibility for volatile mount options and AppArmor, and several correctness fixes. It also includes updates to container event handling, tar extraction, OCI USER validation, sandbox field forwarding, and event topics.
Action needed (1)
securityhighThe CVE-2026-46680 security fix
A security fix for CVE-2026-46680, also identified as GHSA-fqw6-gf59-qr4w, ships in this release.
Check if affected (1)
breakingThe default
seccompsocket policyApplies if you use
seccomp.