A maintenance release that changes several defaults, updates dependencies, and fixes multiple security vulnerabilities. It also includes a fallback to scp for remote sources and destinations in auto mode.
Check if affected (5)
securitycritical
containerdv2.3.2 security fixesApplies if you use
containerd.nerdctlv2.3.3 containscontainerdv2.3.2, which fixes CVE-2026-50195, CVE-2026-53488, CVE-2026-53492, CVE-2026-53489, and CVE-2026-47262.securityhighCVE-2026-53657 and GHSA-2j9v-p4xj-cjw2 guest agent socket fix
Applies if you run a QEMU VM that uses the guest agent socket.
The fix addresses CVE-2026-53657 (GHSA-2j9v-p4xj-cjw2), which allowed an arbitrary user in a QEMU VM to gain root privilege through the guest agent socket.
breaking
containerd.default on non-Linux guestsuser Applies if you run non-Linux guests.
In
limayaml,containerd.no longer defaults touser trueon non-Linux guests.- + 2 more on the release page