containerd
v1.7.35Kubernetes Core2026年9月4日
未公開の脆弱性への対応を含む、セキュリティ重視の保守リリースです。イメージ取得、Windowsのログ処理、ランタイム、性能に関する改善も含まれます。
要対応 (2)
securityCVE-2026-53495 の修正
セキュリティアドバイザリ CVE-2026-53495(GHSA-7jxh-36q5-gcqv)に対応しました。
securityGHSA-rp3h-jf77-q9p4 の修正
セキュリティアドバイザリ GHSA-rp3h-jf77-q9p4 に対応しました。
影響確認 (1)
breakingWindowsでの
ScrubLogs既定有効化Windows上で実行する場合に適用されます。
Windowsでは
ScrubLogsを既定で使用するよう変更しました。
その他の記録済み変更 5 件すべてvalue changes 4 · additions 1
value changes (4)
- * Apply hardening to strip sensitive authentication headers when fetching descriptor URLs ([#14046](https://github.com/containerd/containerd/pull/14046))
- * [
5a2a3a759](https://github.com/containerd/containerd/commit/5a2a3a759b0d2ad8c821b33c3afc20890daf6d81) cri: cancel ExecSync IO drain on context cancellation - * [
9205b1903](https://github.com/containerd/containerd/commit/9205b1903b1336d77864ee658a43b7989f56d13e) archive: skip redundant opaque whiteout walks - * docker fetcher: strip sensitive headers on descriptor URLs ([#14046](https://github.com/containerd/containerd/pull/14046)) * [
b01d66349](https://github.com/containerd/containerd/commit/b01d66349d39f72a9c56696741913bdc5f4332cd) core/remotes/docker: normalize descriptor URL origins * [b5d936dca](https://github.com/containerd/containerd/commit/b5d936dca5e7c5980f2ed0f5114a388ad916a328) core/remotes/docker: strip sensitive headers on desc.urls fetch
additions (1)
- * [
cff94ea40](https://github.com/containerd/containerd/commit/cff94ea40f3959d5f77451b9d72365db44e8d153) ctr: add --scrub-logs flag for Windows
containerdをスタックに追加
対応が必要なリリースが出たときに、週次メールでお知らせします。 今回のセキュリティパッチと破壊的変更も、その一例です。