Upstream update available: runc 1.3.5 → 1.3.6 #5

Closed
opened 2026-06-14 03:33:07 +03:00 by sbelikov · 1 comment
Owner

Upstream update available: runc 1.3.51.3.6

Package

  • Package: runc
  • RPM name: runc
  • Branch: niceos-5.2
  • Current EVR: 1.3.5-1
  • Update class: patch
  • Compare method: python_rpm
  • Update policy: leaf
  • Risk tags: github-upstream

Upstream

Signals

  • Security-relevant keywords detected: True
  • Policy blocked: False
  • Policy reason: -
  • Labels: ai-summary, bot, needs-build, needs-triage, priority/high, security-release, update/patch, upstream-update, upstream/github

NiceSOFT AI preliminary stability analysis

Here's a summary of the key changes in opencontainers/runc v1.3.6 based on the provided sources:


Key Changes in v1.3.6

  1. Version Annotation Fix

    • The org.opencontainers.runc.version annotation in runc features was corrected to remove an extraneous newline character (\n) that could have caused issues with tools parsing the output.
    • This fix ensures compatibility with tools that rely on clean output formatting.
  2. Release Context

    • This version was part of the transition to runc 1.5.0, which introduced stricter policies for major version upgrades (e.g., dropping support for runc 1.4.x).
    • Users are encouraged to migrate to runc 1.5.0 as soon as possible to avoid future compatibility issues.
  3. Other Notable Updates

    • runc version and runc features now include version information about libpathrs (when built with the libpathrs build tag), enhancing transparency for users.
    • The release includes security improvements and bug fixes aligned with the broader transition to the next major version.

Releases & Timeline

  • Release Date: April 2024 (based on GitHub compare page and changelog).
  • Next Major Version: runc 1.5.0 (expected late October 2026), which will drop support for runc 1.4.x.

Important Notes

  • The fix for the newline character is critical for tools like CI/CD pipelines or scripts that parse runc features output.
  • Users should plan migrations to runc 1.5.0 to avoid future compatibility issues.

For full details, refer to the CHANGELOG.md file in the GitHub repository (see link in the query).

  1. GitHub release API: opencontainers/runc v1.3.6
  2. GitHub release API: opencontainers/runc v1.5.0
  3. GitHub tag page: opencontainers/runc v1.3.6
  4. GitHub releases page: opencontainers/runc
  5. GitHub compare page: opencontainers/runc v1.3.5...v1.3.6
  6. British Airways | Book Flights, Holidays, City Breaks & Check In Online
  7. Direct flights to Trinidad (POS) | Book now with British Airways
  8. opencontainers-runc/CHANGELOG.md at main · IgorOffline ... - GitHub
  9. Sing (2016) - IMDb
  10. Sing (2016) - Full cast & crew - IMDb

Upstream release notes / description

This is the sixth patch release of the 1.3.z series of runc. Among some
performance improvements and bugfixes, it includes a fix for a
low-severity vulnerability ([CVE-2026-41579][]) and users are encouraged to
update. As it was a low-severity vulnerability and it was reported by
multiple people, we decided to release it publicly with NO EMBARGO.

Security

This release includes a fix for the following low-severity security issue:

  • [CVE-2026-41579][] allowed a malicious image with a /dev symlink to have
    limited write access to the host filesystem in ways that our analysis
    indicates was too limited to be problematic in practice. This bug was very
    similar to those fixed in [CVE-2025-31133][], [CVE-2025-52565][],
    [CVE-2025-31133][] and was simply missed at the time when we hardened the
    rootfs preparation code. We have conducted a deeper audit and not found any
    other problematic cases.

    This patchset required backports for #5190 and #5285, which were primarily
    code reorganisations that were already backported to runc 1.4 and 1.5.

[CVE-2026-41579]: github.com — GHSA xjvp 4fhw gc47
[CVE-2025-31133]: github.com — GHSA 9493 h29p rfm2
[CVE-2025-52565]: github.com — GHSA qw9x cqr3 wc7r
[CVE-2025-52881]: github.com — GHSA cgrx mc8f 2prm

Fixed

Changed

  • When masking directories with maskPaths, runc will now re-use a single
    tmpfs instance (which is not writable) to reduce the number tmpfs
    superblocks that need to be reaped when containers die (in particular,
    Kubernetes applies masks to per-CPU sysfs directories which get expensive
    quickly). (#5275, #5281)

Static Linking Notices

The runc binary distributed with this release are statically linked with
the following [GNU LGPL-2.1][lgpl-2.1] licensed libraries, with runc acting
as a "work that uses the Library":

[lgpl-2.1]: www.gnu.org — lgpl 2.1.en.html

The versions of these libraries were not modified from their upstream versions,
but in order to comply with the LGPL-2.1 (§6(a)), we have attached the
complete source code for those libraries which (when combined with the attached
runc source code) may be used to exercise your rights under the LGPL-2.1.

However we strongly suggest that you make use of your distribution's packages
or download them from the authoritative upstream sources, especially since
these libraries are related to the security of your containers.


Thanks to the following contributors for making this release possible:

Signed-off-by: Aleksa Sarai cyphar@cyphar.com

NiceOS maintainer checklist

  • Confirm that the detected version is a stable upstream release.
  • Check upstream changelog for security fixes, ABI/API changes and build-system changes.
  • Check ABI/API compatibility and reverse dependencies.
  • Download source into NiceOS lookaside storage.
  • Update Version and related fields in SPECS/*.spec only if policy allows it.
  • Regenerate SOURCES/sources.lock.json, manifests, metadata and SBOM.
  • Build SRPM/RPM in a clean NiceOS buildroot.
  • Run package smoke tests.
  • Link PR/build logs and close this issue after update or triage.

Bot metadata

  • Tool: niceos_upstream_monitor.py 2.1.3-local-websearch-github-release-pages
  • Generated at: 2026-07-07T00:41:32Z
<!-- niceos-upstream-monitor:fingerprint=upstream-update:runc:1.3.6 --> <!-- niceos-upstream-monitor:package=runc --> <!-- niceos-upstream-monitor:current=1.3.5 --> <!-- niceos-upstream-monitor:latest=1.3.6 --> # Upstream update available: `runc` `1.3.5` → `1.3.6` ## Package - Package: `runc` - RPM name: `runc` - Branch: `niceos-5.2` - Current EVR: `1.3.5-1` - Update class: `patch` - Compare method: `python_rpm` - Update policy: `leaf` - Risk tags: `github-upstream` ## Upstream - Upstream type: `github` - Upstream project: `opencontainers/runc` - Upstream URL: <a href="https://github.com/opencontainers/runc" target="_blank" rel="noopener noreferrer">github.com — runc</a> - Detected version: `1.3.6` - Tag/release: `v1.3.6` - Source: `github_release` - Published: `2026-06-13T17:23:17Z` - Release URL: <a href="https://github.com/opencontainers/runc/releases/tag/v1.3.6" target="_blank" rel="noopener noreferrer">github.com — v1.3.6</a> - Source URL: <a href="https://api.github.com/repos/opencontainers/runc/tarball/v1.3.6" target="_blank" rel="noopener noreferrer">api.github.com — v1.3.6</a> - Pre-release: `False` ## Signals - Security-relevant keywords detected: `True` - Policy blocked: `False` - Policy reason: `-` - Labels: `ai-summary, bot, needs-build, needs-triage, priority/high, security-release, update/patch, upstream-update, upstream/github` ## NiceSOFT AI preliminary stability analysis Here's a summary of the key changes in **opencontainers/runc v1.3.6** based on the provided sources: --- ### **Key Changes in v1.3.6** 1. **Version Annotation Fix** - The `org.opencontainers.runc.version` annotation in `runc features` was corrected to remove an extraneous newline character (`\n`) that could have caused issues with tools parsing the output. - This fix ensures compatibility with tools that rely on clean output formatting. 2. **Release Context** - This version was part of the transition to **runc 1.5.0**, which introduced stricter policies for major version upgrades (e.g., dropping support for runc 1.4.x). - Users are encouraged to migrate to runc 1.5.0 as soon as possible to avoid future compatibility issues. 3. **Other Notable Updates** - **`runc version` and `runc features`** now include version information about **libpathrs** (when built with the `libpathrs` build tag), enhancing transparency for users. - The release includes **security improvements** and **bug fixes** aligned with the broader transition to the next major version. --- ### **Releases & Timeline** - **Release Date**: April 2024 (based on GitHub compare page and changelog). - **Next Major Version**: runc 1.5.0 (expected late October 2026), which will drop support for runc 1.4.x. --- ### **Important Notes** - The fix for the newline character is critical for tools like CI/CD pipelines or scripts that parse `runc features` output. - Users should plan migrations to runc 1.5.0 to avoid future compatibility issues. For full details, refer to the **CHANGELOG.md** file in the GitHub repository (see link in the query). ### Источники, найденные web_search 1. <a href="https://github.com/opencontainers/runc/releases/tag/v1.3.6" target="_blank" rel="noopener noreferrer">GitHub release API: opencontainers/runc v1.3.6</a> 2. <a href="https://github.com/opencontainers/runc/releases/tag/v1.5.0" target="_blank" rel="noopener noreferrer">GitHub release API: opencontainers/runc v1.5.0</a> 3. <a href="https://github.com/opencontainers/runc/tree/v1.3.6" target="_blank" rel="noopener noreferrer">GitHub tag page: opencontainers/runc v1.3.6</a> 4. <a href="https://github.com/opencontainers/runc/releases" target="_blank" rel="noopener noreferrer">GitHub releases page: opencontainers/runc</a> 5. <a href="https://github.com/opencontainers/runc/compare/v1.3.5...v1.3.6" target="_blank" rel="noopener noreferrer">GitHub compare page: opencontainers/runc v1.3.5...v1.3.6</a> 6. <a href="https://www.britishairways.com/travel/HOME/public/en_gb/?msockid=180d13f6683b690c1dd9047969e468aa" target="_blank" rel="noopener noreferrer">British Airways | Book Flights, Holidays, City Breaks &amp; Check In Online</a> 7. <a href="https://www.britishairways.com/content/flights/caribbean/trinidad?msockid=180d13f6683b690c1dd9047969e468aa" target="_blank" rel="noopener noreferrer">Direct flights to Trinidad (POS) | Book now with British Airways</a> 8. <a href="https://github.com/IgorOffline/opencontainers-runc/blob/main/CHANGELOG.md" target="_blank" rel="noopener noreferrer">opencontainers-runc/CHANGELOG.md at main · IgorOffline ... - GitHub</a> 9. <a href="https://www.imdb.com/title/tt3470600" target="_blank" rel="noopener noreferrer">Sing (2016) - IMDb</a> 10. <a href="https://www.imdb.com/title/tt3470600/fullcredits/" target="_blank" rel="noopener noreferrer">Sing (2016) - Full cast &amp; crew - IMDb</a> ## Upstream release notes / description This is the sixth patch release of the 1.3.z series of runc. Among some performance improvements and bugfixes, it includes a fix for a low-severity vulnerability ([CVE-2026-41579][]) and users are encouraged to update. As it was a low-severity vulnerability and it was reported by multiple people, we decided to release it publicly with NO EMBARGO. ### Security ### This release includes a fix for the following low-severity security issue: - [CVE-2026-41579][] allowed a malicious image with a `/dev` symlink to have limited write access to the host filesystem in ways that our analysis indicates was too limited to be problematic in practice. This bug was very similar to those fixed in [CVE-2025-31133][], [CVE-2025-52565][], [CVE-2025-31133][] and was simply missed at the time when we hardened the rootfs preparation code. We have conducted a deeper audit and not found any other problematic cases. This patchset required backports for #5190 and #5285, which were primarily code reorganisations that were already backported to runc 1.4 and 1.5. [CVE-2026-41579]: <a href="https://github.com/opencontainers/runc/security/advisories/GHSA-xjvp-4fhw-gc47" target="_blank" rel="noopener noreferrer">github.com — GHSA xjvp 4fhw gc47</a> [CVE-2025-31133]: <a href="https://github.com/opencontainers/runc/security/advisories/GHSA-9493-h29p-rfm2" target="_blank" rel="noopener noreferrer">github.com — GHSA 9493 h29p rfm2</a> [CVE-2025-52565]: <a href="https://github.com/opencontainers/runc/security/advisories/GHSA-qw9x-cqr3-wc7r" target="_blank" rel="noopener noreferrer">github.com — GHSA qw9x cqr3 wc7r</a> [CVE-2025-52881]: <a href="https://github.com/opencontainers/runc/security/advisories/GHSA-cgrx-mc8f-2prm" target="_blank" rel="noopener noreferrer">github.com — GHSA cgrx mc8f 2prm</a> ### Fixed ### - A regression in runc v1.3.0 which can result in a stuck `runc exec` or `runc run` when the container process runs for a short time. (#5208, #5210, #5215) - Various integration test improvements. (#5159, #5188, #5226, #5228, #5239, #5253, #5269, #5288) ### Changed ### - When masking directories with `maskPaths`, runc will now re-use a single `tmpfs` instance (which is not writable) to reduce the number `tmpfs` superblocks that need to be reaped when containers die (in particular, Kubernetes applies masks to per-CPU sysfs directories which get expensive quickly). (#5275, #5281) ### Static Linking Notices ### The `runc` binary distributed with this release are *statically linked* with the following [GNU LGPL-2.1][lgpl-2.1] licensed libraries, with `runc` acting as a "work that uses the Library": [lgpl-2.1]: <a href="https://www.gnu.org/licenses/old-licenses/lgpl-2.1.en.html" target="_blank" rel="noopener noreferrer">www.gnu.org — lgpl 2.1.en.html</a> - <a href="https://github.com/seccomp/libseccomp" target="_blank" rel="noopener noreferrer">libseccomp</a> The versions of these libraries were not modified from their upstream versions, but in order to comply with the LGPL-2.1 (&sect;6(a)), we have attached the complete source code for those libraries which (when combined with the attached runc source code) may be used to exercise your rights under the LGPL-2.1. However we strongly suggest that you make use of your distribution's packages or download them from the authoritative upstream sources, especially since these libraries are related to the security of your containers. - - - Thanks to the following contributors for making this release possible: * Aleksa Sarai <cyphar@cyphar.com> * Ayato Tokubi <atokubi@redhat.com> * Davanum Srinivas <davanum@gmail.com> * Kevin Berry <kpberry11@gmail.com> * Kir Kolyshkin <kolyshkin@gmail.com> * Ricardo Branco <rbranco@suse.de> * Rodrigo Campos Catelin <rodrigo@amutable.com> * Li Fubang <lifubang@acmcoder.com> Signed-off-by: Aleksa Sarai <cyphar@cyphar.com> ## NiceOS maintainer checklist - [ ] Confirm that the detected version is a stable upstream release. - [ ] Check upstream changelog for security fixes, ABI/API changes and build-system changes. - [ ] Check ABI/API compatibility and reverse dependencies. - [ ] Download source into NiceOS lookaside storage. - [ ] Update `Version` and related fields in `SPECS/*.spec` only if policy allows it. - [ ] Regenerate `SOURCES/sources.lock.json`, manifests, metadata and SBOM. - [ ] Build SRPM/RPM in a clean NiceOS buildroot. - [ ] Run package smoke tests. - [ ] Link PR/build logs and close this issue after update or triage. ## Bot metadata - Tool: `niceos_upstream_monitor.py 2.1.3-local-websearch-github-release-pages` - Generated at: `2026-07-07T00:41:32Z`
Author
Owner

Package version is now 1.3.6 and target version was 1.3.6. Closing as resolved.\n\n_Closed by niceos_upstream_monitor.py 1.5 at 2026-07-07T07:34:22Z._

Package version is now `1.3.6` and target version was `1.3.6`. Closing as resolved.\n\n_Closed by `niceos_upstream_monitor.py 1.5` at `2026-07-07T07:34:22Z`._
Sign in to join this conversation.
No description provided.