containerd
v2.0.12Kubernetes Core2026년 9월 4일
공개된 보안 취약점을 수정하고 Windows 기본값을 변경했습니다. 레지스트리 조회를 보호하는 변경과 정확성 및 성능 개선도 포함됩니다.
조치 필요 (2)
securityCVE-2026-53495 보안 취약점 수정
CVE-2026-53495 및 GHSA-7jxh-36q5-gcqv로 공개된 보안 취약점을 수정했습니다.
securityGHSA-rp3h-jf77-q9p4 보안 취약점 수정
GHSA-rp3h-jf77-q9p4로 공개된 보안 취약점을 수정했습니다.
영향 확인 (1)
breakingWindows의
ScrubLogs기본값 변경Windows에서 containerd를 실행하는 경우에 적용됩니다.
Windows에서
ScrubLogs를 기본값으로 사용하도록 변경했습니다.
그 외 기록된 변경 6건 전체value changes 5 · additions 1
value changes (5)
- * [
eebea8c4c](https://github.com/containerd/containerd/commit/eebea8c4c912f44b656c8295c9e6607a19b76650) cri: cancel ExecSync IO drain on context cancellation - * [
6c060c952](https://github.com/containerd/containerd/commit/6c060c9525bd53ce91adc3e1736ab2017bcc689f) archive: skip redundant opaque whiteout walks - * Set SystemTemp env var to config temp on Windows ([#14100](https://github.com/containerd/containerd/pull/14100)) * [
56058341c](https://github.com/containerd/containerd/commit/56058341cb9f21ffe11b1d81099889d39c8e280e) Set SystemTemp env var to config temp on Windows - * docker fetcher: strip sensitive headers on descriptor URLs ([#14045](https://github.com/containerd/containerd/pull/14045)) * [
88c95d56d](https://github.com/containerd/containerd/commit/88c95d56da275becf89bab5b373fbfc080231e49) core/remotes/docker: normalize descriptor URL origins * [7711c3d21](https://github.com/containerd/containerd/commit/7711c3d2188999822928251e154b8570ae9a078d) core/remotes/docker: strip sensitive headers on desc.urls fetch - * remotes: surface OCI error body on HEAD 403 via GET fallback ([#13749](https://github.com/containerd/containerd/pull/13749)) * [
71a73c8a0](https://github.com/containerd/containerd/commit/71a73c8a0f3818e30d873e645b0335e4aa7913ba) remotes: surface OCI error body on HEAD 403 via GET fallback
additions (1)
- add --scrub-logs flag for Windows
containerd 스택에 추가
조치가 필요한 릴리스가 나왔을 때 주간 메일로 알려드립니다. 이번 릴리스의 보안 패치와 브레이킹 체인지 같은 것들입니다.