containerd
v2.3.5Kubernetes Core2026年9月4日
開示されたセキュリティ修正を含む保守リリースです。信頼性と互換性の修正、依存関係の更新があり、移行作業を必要とする変更はありません。
要対応 (1)
securityCVE-2026-53495への対応
containerdでCVE-2026-53495に対応しました。関連するアドバイザリはGHSA-rp3h-jf77-q9p4です。
その他の記録済み変更 14 件すべてfixes 7 · value changes 7
fixes (7)
- Fix data races and a deadlock in the byte stream helpers
- snapshots/erofs: advertise the erofs OS feature from the snapshotter plugin
- pkg/tracing: handle error and typed-nil Stringer attributes
- pkg/oci: resolve rootfs symlinks for user lookup
- ensure that the final config version is the higest in the config list
- fix(runtime): apply load timeout to load shim
- Fix WS2022 compat on hosts past the latest LTSC
value changes (7)
- cri: cancel ExecSync IO drain on context cancellation
- archive: skip redundant opaque whiteout walks
- update runc to v1.5.1
- vendor: github.com/containerd/platforms v1.0.0-rc.5
- docker fetcher: strip sensitive headers on descriptor URLs
- update runhcs to v0.15.0-rc.4
- Add more context to the shim delete error
containerdをスタックに追加
対応が必要なリリースが出たときに、週次メールでお知らせします。 今回のセキュリティパッチも、その一例です。