Containers

containerd: what changed

In the last 90 days, 15 summarized changes: 1 breaking changes, 7 security advisories, 2 end-of-life notices, 4 deprecations, 1 fixes. Stackdiff reads containerd's own feeds (github.com) and writes two sentences per change with a link to the source; it never republishes release notes. Sources last checked .

Needs attention

Breaking changes, security advisories, end-of-life and license changes from the last 90 days, worst first.

2.4.0-beta.0Breakinghigh
containerd 2.4.0-beta.0
1.7.35Securitymedium
GHSA-7jxh-36q5-gcqv: containerd: CRI ExecSync Goroutine Leak Leads to Node-Level Denial of Service
1.7.35Securitymedium
containerd 1.7.35
2.0.12Securitymedium
containerd 2.0.12
2.3.5Securitymedium
containerd 2.3.5
2.2.8Securitymedium
containerd 2.2.8
1.7.33Securitymedium
GHSA-xhf5-7wjv-pqxp: containerd CRI — image-config `LABEL` flows to restart-monitor `binary://` logger: host-root command execution from an image pull
1.7.33Securitymedium
GHSA-jpcc-p29g-p8mq: containerd image-triggered runtime DoS via unbounded group parsing
2.2End of lifehigh
containerd 2.2 reaches end of life on 2026-11-06
ActionPlan the upgrade before the date.
1.7End of lifehigh
containerd 1.7 reached end of life on 2026-09-01
ActionPlan the upgrade before the date.

End of life

Support windows from endoflife.date. An entry appears the day a date enters the 120-day horizon.

CycleWhatPublished
2.2containerd 2.2 reaches end of life on 2026-11-06
1.7containerd 1.7 reached end of life on 2026-09-01

Latest changes

Newest first, every type. Releases and fixes sit below anything that can hurt you in the weekly brief; here they are in order.

2.2End of lifehigh
containerd 2.2 reaches end of life on 2026-11-06
ActionPlan the upgrade before the date.
1.7.35Securitymedium
GHSA-7jxh-36q5-gcqv: containerd: CRI ExecSync Goroutine Leak Leads to Node-Level Denial of Service
1.7.35Securitymedium
containerd 1.7.35
2.0.12Securitymedium
containerd 2.0.12
2.3.5Securitymedium
containerd 2.3.5
2.2.8Securitymedium
containerd 2.2.8
1.7End of lifehigh
containerd 1.7 reached end of life on 2026-09-01
ActionPlan the upgrade before the date.
1.12.0-rc.0Deprecatedmedium
containerd API 1.12.0-rc.0
2.2.7Deprecatedmedium
containerd 2.2.7
2.3.4Deprecatedmedium
containerd 2.3.4
2.4.0-beta.0Breakinghigh
containerd 2.4.0-beta.0
1.12.0-beta.0Deprecatedmedium
containerd API 1.12.0-beta.0
2.3.3Fix
containerd 2.3.3
1.7.33Securitymedium
GHSA-xhf5-7wjv-pqxp: containerd CRI — image-config `LABEL` flows to restart-monitor `binary://` logger: host-root command execution from an image pull
1.7.33Securitymedium
GHSA-jpcc-p29g-p8mq: containerd image-triggered runtime DoS via unbounded group parsing
1.7.32Securitymedium
GHSA-fqw6-gf59-qr4w: containerd user ID handling bypass allows runAsNonRoot evasion
1.7.29Securitymedium
GHSA-m6hq-p25p-ffr2: containerd CRI server: Host memory exhaustion through Attach goroutine leak
1.7.29Securitymedium
GHSA-pwhc-rpq9-4c8w: containerd affected by a local privilege escalation via wide permissions on CRI directory
1.6.38Securitymedium
GHSA-265r-hfxg-fhmg: containerd has an integer overflow in User ID handling
1.3.10Securitymedium
GHSA-6g2q-w5j3-fwh4: containerd environment variable leak
1.6.26Securitymedium
GHSA-7ww5-4wqc-m92c: containerd allows RAPL to be accessible to a container
1.5.18Securitymedium
GHSA-259w-8hf6-59c2: OCI image importer memory exhaustion in github.com/containerd/containerd
1.5.18Securitymedium
GHSA-hmfx-3pcx-653p: Supplementary groups are not set up properly in github.com/containerd/containerd
1.5.16Securitymedium
GHSA-2qjp-425j-52j9: containerd CRI stream server vulnerable to host memory exhaustion via terminal
1.5.13Securitymedium
GHSA-5ffw-gxpp-mxpf: containerd CRI plugin: Host memory exhaustion through ExecSync
1.4.13Securitymedium
GHSA-crp2-qrr5-8pq7: containerd CRI plugin: Insecure handling of image volumes
1.2.14Securitymedium
GHSA-742w-89gc-8m9c: containerd v1.2.x can be coerced into leaking credentials during image pull
1.4.12Securitymedium
GHSA-5j5w-g665-5m35: Ambiguous OCI manifest parsing
1.4.11Securitymedium
GHSA-c2h3-6mxw-7mvq: Insufficiently restricted permissions on plugin directories
1.4.8Securitymedium
GHSA-c72p-9xmj-rx3w: Archive package allows chmod of file outside of unpack target directory

Where Stackdiff reads containerd

Only what the vendor publishes for machines. Excerpts are capped, summaries are our own two sentences, and every line links back.

Get containerd changes in your Monday brief

Add containerd and the rest of your stack; breaking changes and CVEs go out the moment they're seen, everything else on Monday.

Get your first brief

Other containers tools