Debian Patches

Status for containerd/2.1.9+ds1-5

Patch Description Author Forwarded Bugs Origin Last update
0001-disable-windows-support-in-ctr-metric.patch disable windows support Shengjing Zhu <zhsj@debian.org> not-needed 2020-09-16
0004-Disable-zfs-plugin.patch Disable zfs plugin Reinhard Tartler <siretart@tauware.de> not-needed 2025-08-09
0009-Skip-some-tests-that-fail-in-Debian.patch Skip some tests that fail in Debian Reinhard Tartler <siretart@tauware.de> not-needed 2024-08-10
0011-Add-missing-sources-for-containerd-zfs-aufs.patch Add missing sources for containerd/{zfs,aufs} Reinhard Tartler <siretart@tauware.de> not-needed 2024-09-28
0005-Fix-format-string-issue.patch Fix format string issue Reinhard Tartler <siretart@tauware.de> not-needed 2026-03-19
0006-Use-cni-path-usr-lib-cni.patch Use cni path '/usr/lib/cni' Reinhard Tartler <siretart@tauware.de> not-needed 2026-03-20
0007-pkg-oci-update-TestOpenBoundedUserFileCapsReads-to-u.patch pkg/oci: update TestOpenBoundedUserFileCapsReads to use newlined data

This test verifies the maximum file-size constraints that were added in
CVE-2026-53488. However, github.com/moby/sys adds line-length constraints
(1M) that may hit before the file-size limit is reached if the data does
not contain newlines, resulting in 'bufio.Scanner: token too long'.

This patch updates the test to use data that includes newlines (via comment
lines) to make sure it tests the file-size constraints rather than line-length
limits.
Sebastiaan van Stijn <github@gone.nl> not-needed debian upstream backport, https://github.com/containerd/containerd/commit/7a7aebfcbf6d3ce24d7b50eb2d7f9676b26c91d5 2026-09-15
0008-cri-cancel-ExecSync-IO-drain-on-context-cancellation.patch cri: cancel ExecSync IO drain on context cancellation (CVE-2026-53495)
When drain_exec_sync_io_timeout is 0 and a child process holds the
pipe, drainExecSyncIO blocks forever even after the client disconnects.
Add ctx.Done() to the select to allow cancellation, and use a deferred
context for Process.Delete cleanup when the original context is already
canceled.
XlabAI <xlabai@tencent.com> not-needed debian backport, https://github.com/containerd/containerd/commit/ff39a972369e2f12fae561a58d658bbf8f2bc318 2026-06-09
0012-Bound-image-handlers-concurrency-and-references-CVE-2026-53493.patch Bound image handlers concurrency and references (CVE-2026-53493)
A crafted OCI index graph can force very high CPU/memory usage during
PullImage (before container start), causing long ContainerCreating stalls
and, at larger sizes, node/runtime instability.

Bound Dispatch concurrency and references:
Traverse breadth-first, one level at a time. Acquire the limiter before
starting each handler goroutine. Default to 32 concurrent handlers when
no limiter is provided. Children wait until every handler in the current
level finishes.

Bound Walk references:
Return an error wrapping ErrResourceExhausted when the walk exceeds
10,000 references. Preserve duplicate visits and count every reference
toward the limit across recursive calls and roots.
Chris Henzie <chrishenzie@gmail.com> not-needed debian backport, https://github.com/containerd/containerd/commit/4f5f32636d47f051751065cf824a10da70c619fe 2026-07-28

All known versions for source package 'containerd'

Links