containerd
v1.7.35Kubernetes Core2026년 9월 4일
보안에 초점을 둔 유지 보수 릴리스로, 공개되지 않은 취약점 수정과 이미지 가져오기 보강이 포함됩니다. Windows 로그 기본값이 바뀌고 실행 시간과 성능도 개선됩니다.
조치 필요 (2)
securityCVE-2026-53495 취약점 수정
CVE-2026-53495 취약점이 수정되었습니다.
securityGHSA-rp3h-jf77-q9p4 취약점 수정
GHSA-rp3h-jf77-q9p4 보안 취약점이 수정되었습니다.
영향 확인 (1)
breakingWindows의
ScrubLogs기본 사용Windows에서 실행하는 경우 적용됩니다.
Windows에서는
ScrubLogs를 기본으로 사용하도록 바뀌었습니다.
그 외 기록된 변경 5건 전체value changes 4 · additions 1
value changes (4)
- * Apply hardening to strip sensitive authentication headers when fetching descriptor URLs ([#14046](https://github.com/containerd/containerd/pull/14046))
- * [
5a2a3a759](https://github.com/containerd/containerd/commit/5a2a3a759b0d2ad8c821b33c3afc20890daf6d81) cri: cancel ExecSync IO drain on context cancellation - * [
9205b1903](https://github.com/containerd/containerd/commit/9205b1903b1336d77864ee658a43b7989f56d13e) archive: skip redundant opaque whiteout walks - * docker fetcher: strip sensitive headers on descriptor URLs ([#14046](https://github.com/containerd/containerd/pull/14046)) * [
b01d66349](https://github.com/containerd/containerd/commit/b01d66349d39f72a9c56696741913bdc5f4332cd) core/remotes/docker: normalize descriptor URL origins * [b5d936dca](https://github.com/containerd/containerd/commit/b5d936dca5e7c5980f2ed0f5114a388ad916a328) core/remotes/docker: strip sensitive headers on desc.urls fetch
additions (1)
- * [
cff94ea40](https://github.com/containerd/containerd/commit/cff94ea40f3959d5f77451b9d72365db44e8d153) ctr: add --scrub-logs flag for Windows
containerd 스택에 추가
조치가 필요한 릴리스가 나왔을 때 주간 메일로 알려드립니다. 이번 릴리스의 보안 패치와 브레이킹 체인지 같은 것들입니다.