Upstream update available: runc 1.3.5 → 1.3.6 #5
Labels
No labels
ai-summary
bot
needs-build
needs-triage
priority/high
security-release
update/minor
update/patch
upstream-update
upstream/github
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
rpms/runc#5
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Upstream update available:
runc1.3.5→1.3.6Package
runcruncniceos-5.21.3.5-1patchpython_rpmleafgithub-upstreamUpstream
githubopencontainers/runc1.3.6v1.3.6github_release2026-06-13T17:23:17ZFalseSignals
TrueFalse-ai-summary, bot, needs-build, needs-triage, priority/high, security-release, update/patch, upstream-update, upstream/githubNiceSOFT AI preliminary stability analysis
Here's a summary of the key changes in opencontainers/runc v1.3.6 based on the provided sources:
Key Changes in v1.3.6
Version Annotation Fix
org.opencontainers.runc.versionannotation inrunc featureswas corrected to remove an extraneous newline character (\n) that could have caused issues with tools parsing the output.Release Context
Other Notable Updates
runc versionandrunc featuresnow include version information about libpathrs (when built with thelibpathrsbuild tag), enhancing transparency for users.Releases & Timeline
Important Notes
runc featuresoutput.For full details, refer to the CHANGELOG.md file in the GitHub repository (see link in the query).
Источники, найденные web_search
Upstream release notes / description
This is the sixth patch release of the 1.3.z series of runc. Among some
performance improvements and bugfixes, it includes a fix for a
low-severity vulnerability ([CVE-2026-41579][]) and users are encouraged to
update. As it was a low-severity vulnerability and it was reported by
multiple people, we decided to release it publicly with NO EMBARGO.
Security
This release includes a fix for the following low-severity security issue:
[CVE-2026-41579][] allowed a malicious image with a
/devsymlink to havelimited write access to the host filesystem in ways that our analysis
indicates was too limited to be problematic in practice. This bug was very
similar to those fixed in [CVE-2025-31133][], [CVE-2025-52565][],
[CVE-2025-31133][] and was simply missed at the time when we hardened the
rootfs preparation code. We have conducted a deeper audit and not found any
other problematic cases.
This patchset required backports for #5190 and #5285, which were primarily
code reorganisations that were already backported to runc 1.4 and 1.5.
[CVE-2026-41579]: github.com — GHSA xjvp 4fhw gc47
[CVE-2025-31133]: github.com — GHSA 9493 h29p rfm2
[CVE-2025-52565]: github.com — GHSA qw9x cqr3 wc7r
[CVE-2025-52881]: github.com — GHSA cgrx mc8f 2prm
Fixed
runc execorrunc runwhen the container process runs for a short time. (#5208,#5210, #5215)
#5253, #5269, #5288)
Changed
maskPaths, runc will now re-use a singletmpfsinstance (which is not writable) to reduce the numbertmpfssuperblocks that need to be reaped when containers die (in particular,
Kubernetes applies masks to per-CPU sysfs directories which get expensive
quickly). (#5275, #5281)
Static Linking Notices
The
runcbinary distributed with this release are statically linked withthe following [GNU LGPL-2.1][lgpl-2.1] licensed libraries, with
runcactingas a "work that uses the Library":
[lgpl-2.1]: www.gnu.org — lgpl 2.1.en.html
The versions of these libraries were not modified from their upstream versions,
but in order to comply with the LGPL-2.1 (§6(a)), we have attached the
complete source code for those libraries which (when combined with the attached
runc source code) may be used to exercise your rights under the LGPL-2.1.
However we strongly suggest that you make use of your distribution's packages
or download them from the authoritative upstream sources, especially since
these libraries are related to the security of your containers.
Thanks to the following contributors for making this release possible:
Signed-off-by: Aleksa Sarai cyphar@cyphar.com
NiceOS maintainer checklist
Versionand related fields inSPECS/*.speconly if policy allows it.SOURCES/sources.lock.json, manifests, metadata and SBOM.Bot metadata
niceos_upstream_monitor.py 2.1.3-local-websearch-github-release-pages2026-07-07T00:41:32ZPackage version is now
1.3.6and target version was1.3.6. Closing as resolved.\n\n_Closed byniceos_upstream_monitor.py 1.5at2026-07-07T07:34:22Z._