Debian Patches
Status for containerd/2.1.9+ds1-5
| Patch | Description | Author | Forwarded | Bugs | Origin | Last update |
|---|---|---|---|---|---|---|
| 0001-disable-windows-support-in-ctr-metric.patch | disable windows support | Shengjing Zhu <zhsj@debian.org> | not-needed | 2020-09-16 | ||
| 0004-Disable-zfs-plugin.patch | Disable zfs plugin | Reinhard Tartler <siretart@tauware.de> | not-needed | 2025-08-09 | ||
| 0009-Skip-some-tests-that-fail-in-Debian.patch | Skip some tests that fail in Debian | Reinhard Tartler <siretart@tauware.de> | not-needed | 2024-08-10 | ||
| 0011-Add-missing-sources-for-containerd-zfs-aufs.patch | Add missing sources for containerd/{zfs,aufs} | Reinhard Tartler <siretart@tauware.de> | not-needed | 2024-09-28 | ||
| 0005-Fix-format-string-issue.patch | Fix format string issue | Reinhard Tartler <siretart@tauware.de> | not-needed | 2026-03-19 | ||
| 0006-Use-cni-path-usr-lib-cni.patch | Use cni path '/usr/lib/cni' | Reinhard Tartler <siretart@tauware.de> | not-needed | 2026-03-20 | ||
| 0007-pkg-oci-update-TestOpenBoundedUserFileCapsReads-to-u.patch | pkg/oci: update TestOpenBoundedUserFileCapsReads to use newlined data This test verifies the maximum file-size constraints that were added in CVE-2026-53488. However, github.com/moby/sys adds line-length constraints (1M) that may hit before the file-size limit is reached if the data does not contain newlines, resulting in 'bufio.Scanner: token too long'. This patch updates the test to use data that includes newlines (via comment lines) to make sure it tests the file-size constraints rather than line-length limits. |
Sebastiaan van Stijn <github@gone.nl> | not-needed | debian upstream | backport, https://github.com/containerd/containerd/commit/7a7aebfcbf6d3ce24d7b50eb2d7f9676b26c91d5 | 2026-09-15 |
| 0008-cri-cancel-ExecSync-IO-drain-on-context-cancellation.patch | cri: cancel ExecSync IO drain on context cancellation (CVE-2026-53495) When drain_exec_sync_io_timeout is 0 and a child process holds the pipe, drainExecSyncIO blocks forever even after the client disconnects. Add ctx.Done() to the select to allow cancellation, and use a deferred context for Process.Delete cleanup when the original context is already canceled. |
XlabAI <xlabai@tencent.com> | not-needed | debian | backport, https://github.com/containerd/containerd/commit/ff39a972369e2f12fae561a58d658bbf8f2bc318 | 2026-06-09 |
| 0012-Bound-image-handlers-concurrency-and-references-CVE-2026-53493.patch | Bound image handlers concurrency and references (CVE-2026-53493) A crafted OCI index graph can force very high CPU/memory usage during PullImage (before container start), causing long ContainerCreating stalls and, at larger sizes, node/runtime instability. Bound Dispatch concurrency and references: Traverse breadth-first, one level at a time. Acquire the limiter before starting each handler goroutine. Default to 32 concurrent handlers when no limiter is provided. Children wait until every handler in the current level finishes. Bound Walk references: Return an error wrapping ErrResourceExhausted when the walk exceeds 10,000 references. Preserve duplicate visits and count every reference toward the limit across recursive calls and roots. |
Chris Henzie <chrishenzie@gmail.com> | not-needed | debian | backport, https://github.com/containerd/containerd/commit/4f5f32636d47f051751065cf824a10da70c619fe | 2026-07-28 |
All known versions for source package 'containerd'
- 2.1.9+ds1-5 (sid)
- 2.1.9+ds1-3 (forky)
- 1.7.24~ds1-6+deb13u1 (trixie-security, trixie-proposed-updates, trixie)
- 1.6.20~ds1-1+deb12u3 (bookworm)
- 1.6.20~ds1-1+deb12u2 (bookworm-security)
