Ubuntu alert USN-7983-1 (containerd, containerd-app)
| From: | noreply+usn-bot@canonical.com | |
| To: | ubuntu-security-announce@lists.ubuntu.com | |
| Subject: | [USN-7983-1] containerd vulnerabilities | |
| Date: | Thu, 29 Jan 2026 11:06:32 +0000 | |
| Message-ID: | <E1vlPr6-0001lu-Dy@lists.ubuntu.com> |
========================================================================== Ubuntu Security Notice USN-7983-1 January 29, 2026 containerd, containerd-app vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Several security issues were fixed in containerd. Software Description: - containerd: open and reliable container runtime library - containerd-app: open and reliable container runtime Details: David Leadbeater discovered that containerd incorrectly set certain directory path permissions. An attacker could possibly use this issue to achieve unauthorised access to the files. (CVE-2024-25621) It was discovered that containerd did not properly handle the execution of the goroutine of container attach. An attacker could possibly use this issue to cause a denial of service. (CVE-2025-64329) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.10 containerd 2.1.3-0ubuntu3.1 golang-github-containerd-containerd-dev 1.7.24~ds1-8ubuntu1.1 Ubuntu 24.04 LTS containerd 1.7.28-0ubuntu1~24.04.2 golang-github-containerd-containerd-dev 1.6.24~ds1-1ubuntu1.3+esm2 Available with Ubuntu Pro Ubuntu 22.04 LTS containerd 1.7.28-0ubuntu1~22.04.1+esm1 Available with Ubuntu Pro golang-github-containerd-containerd-dev 1.6.12-0ubuntu1~22.04.10 Ubuntu 20.04 LTS containerd 1.7.24-0ubuntu1~20.04.2+esm1 Available with Ubuntu Pro golang-github-containerd-containerd-dev 1.6.12-0ubuntu1~20.04.8+esm1 Available with Ubuntu Pro Ubuntu 18.04 LTS containerd 1.6.12-0ubuntu1~18.04.1+esm3 Available with Ubuntu Pro golang-github-containerd-containerd-dev 1.6.12-0ubuntu1~18.04.1+esm3 Available with Ubuntu Pro Ubuntu 16.04 LTS containerd 1.2.6-0ubuntu1~16.04.6+esm6 Available with Ubuntu Pro golang-github-docker-containerd-dev 1.2.6-0ubuntu1~16.04.6+esm6 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7983-1 CVE-2024-25621, CVE-2025-64329 Package Information: https://launchpad.net/ubuntu/+source/containerd/1.7.24~ds... https://launchpad.net/ubuntu/+source/containerd-app/2.1.3...
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAml7PsoACgkQcpJm3tlz hgG8PA/8CF6/3FeHuJBCjC19e+w8TYWzq2+vKqa8mlmeu22uOFrx929ro2I8i33V xHdUC+RFtVKMiVIXUVCQZV2O1CXa1c1D5EUKDneBCP+4Ya1FN3ql9+nw/YxYO3/n e7NGEQoJI3c8RiioupQOY9fuwN0UocnmS7y/66pIKZrLBR3OdbJ51/xJyGv4mIl8 ywDjoSn9G8WeGhHfGZWA8K5vk9+foacPlt8IsyNCAK8IbEmEYG5Dyj54l8sSeYKx 9R615o4Un0uSbgr5CAhd5Di+8LunmcS++A2ve41KkyTSXInFUBUucdsA95ANcmTz pSwO3SyPOXnbjvLvC81gXDe7T+qMMno5nTPDnLNnTntkYbXsYluA7n7kLdL8PZcg a1FKOB1W7G0ux3Z1+byX62fhYK23fonqERW1fPKk6sz70EoMWoD4uTAC4pUuGD9M kKKd7AWtlOmv1NnTaC066PPaO31chbBCXh8RvFKDphxXXaA2W9aKrWc6xBOqlLaJ HeWPyEq0iV9HdUtAhDXo1soXUpp7zCJFsokiNj4el0whAloip74ODqF1RsiB8eNx AH+e/r/wMSwwiMTMwPjuVmBhfs6LIVBFlTMzYQtmOj8H3EWtTZb//7YNNK9Vlxir r44ZvuzHgMODjcdsbVf2z8hkXhyeZYPQ4I76Ni0n94IzupIJFxs= =3dMA -----END PGP SIGNATURE-----
