Upstream update available: containerd 2.1.4 → 2.3.2 #8
Labels
No labels
ai-summary
auto-analysis
bot
cve
match-cpe-range
needs-build
needs-triage
priority/high
priority/medium
security
security-release
severity-high
source-niceos-scan
source-nvd
update/minor
update/patch
upstream-update
upstream/github
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
rpms/containerd#8
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Upstream update available:
containerd2.1.4→2.3.2Package
containerdcontainerdniceos-5.22.1.4-1minorpython_rpmleafgithub-upstreamUpstream
githubcontainerd/containerd2.3.2v2.3.2github_release_latest2026-06-18T23:16:02ZFalseSignals
TrueFalse-ai-summary, bot, needs-build, needs-triage, priority/high, security-release, update/minor, upstream-update, upstream/githubNiceSOFT AI preliminary stability analysis
Risk Assessment for
containerdUpdate in NAIOS.OS1. Key Details
containerd2.1.42.3.2(minor patch)github-upstream(indicating upstream security updates)True(indicating security-related changes)2. Risk Evaluation
a. Security Risks (Medium)
CVEs Included:
The update includes security patches for the following vulnerabilities:
Impact:
The update addresses critical security vulnerabilities in the container runtime. A single unpatched vulnerability could compromise the entire system.
Recommendation:
Apply the update immediately to mitigate risks. Monitor for new vulnerabilities in the future.
b. ABI/API Risks (Low)
No ABI Changes:
The update is a minor patch (no version bump). No ABI or API changes are documented.
Impact:
The runtime remains compatible with previous versions. No risks from incompatible changes.
Recommendation:
No action required for ABI/API risks. Proceed with the update as it does not affect compatibility.
c. RPM Build Risks (Low)
No Changes to RPM:
The update does not alter the RPM spec files or BuildRequires.
Impact:
The RPM build process remains unaffected. No conflicts or changes to dependencies.
Recommendation:
Proceed with the update without modifying RPMs.
3. Final Recommendation
Apply the
containerd 2.3.2update to ensure security and stability. Monitor for future updates and verify compatibility with existing systems.Action Plan:
sudo apt upgrade containerdfor Debian/Ubuntu).containerd --versionto confirm the new version.containerd 2.4.x).4. Summary
This update is critical for securing the container runtime and mitigating potential vulnerabilities.
Источники, найденные web_search
Upstream release notes / description
Welcome to the v2.3.2 release of containerd!
The second patch release for containerd 2.3 contains various fixes
and updates including security patches.
Security Updates
Highlights
Image Distribution
Runtime
Please try out the release binaries and report any issues at
github.com — issues.
Contributors
Changes
30 commits
fb8ca00b0Prepare release notes for v2.3.29c69960baMerge commit from fork0f6251520Merge commit from fork91d7471e2cri: filter CDI annotations on checkpoint restore7c2e086bfMerge commit from forkdae67765fcri: do not re-tag restored checkpoints94aa1e2c1Merge commit from fork09599078fcri: make checkpoint restore robust to unexpected archive contente1fdb8d22Merge commit from forkff1d116efBound user-database file reads in openUserFiled156e07cbMerge commit from forkf99aad54aDo not propagate reserved labels from image configs0b9469501[release/2.3] vendor: golang.org/x/crypto v0.53.0983bbddc1resolver: retry on transient network errors3f76f2dc1update runc binary to v1.4.38a49dfe85update go to 1.26.45aa6bb2b7remove 1.26.2 from CI builds as it is not supported any longer due to the dependencybfb8aebc0Configure udevd children-max for root-test62ceafff0core/runtime/v2: fix race on Windows deferredPipeConnection.c in Read9b0c0dc58runc-shim: don't hold the service lock across runc createf588bc6fbcontrib/checkpoint: increase timeouts to 30sDependency Changes
...[truncated 806 chars]
NiceOS maintainer checklist
Versionand related fields inSPECS/*.speconly if policy allows it.SOURCES/sources.lock.json, manifests, metadata and SBOM.Bot metadata
niceos_upstream_monitor.py 2.1.3-local-websearch-github-release-pages2026-07-06T23:13:08ZPackage version is now
2.3.2and target version was2.3.2. Closing as resolved.\n\n_Closed byniceos_upstream_monitor.py 1.5at2026-07-07T13:52:58Z._