containerd v1.7.33

v1.7.33

containerd 1.7.33

Changed 2
  • Update runc binary to v1.3.6
  • Update Go to 1.26.4 and 1.25.11
Fixed 2
  • Bound user-database file reads in openBoundedUserFile
  • Do not propagate reserved labels from image configs
Security 3
  • Address CVE-2026-53488 in containerd
  • Address CVE-2026-47262 in containerd
  • Address CVE-2026-34986 in go-jose by bumping go-jose/go-jose/v3 to v3.0.5

Welcome to the v1.7.33 release of containerd!

The thirty-third patch release for containerd 1.7 contains various fixes and updates including security patches.

Security Updates

Please try out the release binaries and report any issues at https://github.com/containerd/containerd/issues.

Contributors
  • Samuel Karp
  • Chris Henzie
  • Akihiro Suda
  • Akhil Mohan
  • Ben Cressey
  • Davanum Srinivas
  • Sopho Merkviladze
Changes
  • Prepare release notes for v1.7.33 (#13631)
    • 7517e6737 Prepare release notes for v1.7.33
    • ab306518a Merge commit from fork
    • d34cdafda Merge commit from fork
    • 9ab2b7a89 Bound user-database file reads in openBoundedUserFile
    • 1e9806f90 Merge commit from fork
    • 4d8ba4d23 Do not propagate reserved labels from image configs
  • update runc binary to v1.3.6 (#13615)
  • update go to 1.26.4/1.25.11 (#13579)
  • Configure udevd children-max for root-test (#13564)
    • e884e964e Configure udevd children-max for root-test
  • Clean up disk space in node e2e workflow (#13552)
    • b9e756888 Clean up disk space in node e2e workflow
  • Bump go-jose/go-jose/v3 to v3.0.5 to fix GHSA-78h2-9frx-2jm8 (#13467)
    • 4dfc1844e Bump go-jose to v3.0.5 to address CVE-2026-34986
Dependency Changes
  • github.com/go-jose/go-jose/v3 v3.0.4 -> v3.0.5

Previous release can be found at v1.7.32

View original

Upgraded? How did it go?

Discussion