Skip to content

chore(deps): update module github.com/containerd/containerd to v1.7.36 [security] (release-2.4) - #389

Open
crossplane-renovate[bot] wants to merge 1 commit into
release-2.4from
renovate/release-2.4-vulnerable-dependencies
Open

crossplane-renovate[bot] wants to merge 1 commit into
release-2.4from
renovate/release-2.4-vulnerable-dependencies

Conversation

@crossplane-renovate

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
github.com/containerd/containerd v1.7.35 → v1.7.36 age confidence

Containerd has image-pull DoS via crafted OCI index graph amplification

CVE-2026-53493 / GHSA-pg57-6jwg-q645

More information

Details

Impact

A vulnerability exists in containerd's image pull handlers where a crafted OCI image index containing deeply nested or heavily fanned-out descriptor graphs can cause unbounded CPU and memory consumption. During the PullImage operation, the recursive traversal and processing of child descriptors lack sufficient depth and breadth limits, and fail to adequately deduplicate identical descriptors. This unbounded traversal leads to excessive resource allocation.

Consequently, pulling a malicious image reference can result in prolonged stalls during container creation and significant resource pressure on the host system. This issue occurs entirely during the image pull phase, prior to any container execution.

Patches

This bug has been fixed in containerd 2.4.1, 2.3.6, 2.2.9, 2.0.13, and 1.7.36. Users should update to these versions to resolve the issue.

Workarounds

There are no known workarounds for this issue. Users are advised to only pull trusted images from known registries until the patch can be applied.

Credits

The containerd project would like to thank Jakub Ciolek at ElevenLabs and @​jlgore who independently discovered and responsibly disclosed this issue in accordance with the containerd security policy.

For more information

If you have any questions or comments about this advisory:

To report a security issue in containerd:

Severity

  • CVSS Score: 6.9 / 10 (Medium)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Containerd has image-pull DoS via crafted OCI index graph amplification

CVE-2026-53493 / GHSA-pg57-6jwg-q645

More information

Details

Impact

A vulnerability exists in containerd's image pull handlers where a crafted OCI image index containing deeply nested or heavily fanned-out descriptor graphs can cause unbounded CPU and memory consumption. During the PullImage operation, the recursive traversal and processing of child descriptors lack sufficient depth and breadth limits, and fail to adequately deduplicate identical descriptors. This unbounded traversal leads to excessive resource allocation.

Consequently, pulling a malicious image reference can result in prolonged stalls during container creation and significant resource pressure on the host system. This issue occurs entirely during the image pull phase, prior to any container execution.

Patches

This bug has been fixed in containerd 2.4.1, 2.3.6, 2.2.9, 2.0.13, and 1.7.36. Users should update to these versions to resolve the issue.

Workarounds

There are no known workarounds for this issue. Users are advised to only pull trusted images from known registries until the patch can be applied.

Credits

The containerd project would like to thank Jakub Ciolek at ElevenLabs and @​jlgore who independently discovered and responsibly disclosed this issue in accordance with the containerd security policy.

For more information

If you have any questions or comments about this advisory:

To report a security issue in containerd:

Severity

  • CVSS Score: 6.9 / 10 (Medium)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Release Notes

containerd/containerd (github.com/containerd/containerd)

v1.7.36: containerd 1.7.36

Compare Source

Welcome to the v1.7.36 release of containerd!

The thirty-sixth patch release for containerd 1.7 contains various fixes
and updates including a security patch.

Security Updates
Highlights
Image Storage
  • Ensure all layers are fetched when multiple manifests in an index share a config descriptor (#​14142)
Runtime
  • Mask /proc/interrupts and CPU thermal throttle sysfs paths in Linux containers by default (#​14184)

Please try out the release binaries and report any issues at
https://github.com/containerd/containerd/issues.

Contributors
  • Samuel Karp
  • Chris Henzie
  • Derek McGowan
Changes
9 commits

  • b0ab39c205 Prepare release notes for v1.7.36
  • 670a5de22f Merge commit from fork
  • a3a39e5873 Bound Walk references
  • ffc673f859 Bound Dispatch concurrency and references
  • pkg/oci: mask thermal interrupt info (#​14184)
  • core/unpack: fetch layers of every config-sharing manifest (#​14142)
    • 4684c683c2 core/unpack: fetch layers of every config-sharing manifest
    • 7fba9f7c3c Create new imagetest package

Dependency Changes

This release has no dependency changes

Previous release can be found at v1.7.35


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

@crossplane-renovate
crossplane-renovate Bot requested review from adamwg and removed request for a team September 26, 2026 08:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants