|
|
Log in / Subscribe / Register

Ubuntu alert USN-8471-1 (containerd)

From:  noreply+usn-bot--- via ubuntu-security-announce <ubuntu-security-announce@lists.ubuntu.com>
To:  ubuntu-security-announce@lists.ubuntu.com
Subject:  [USN-8471-1] containerd vulnerabilities
Date:  Thu, 25 Jun 2026 14:29:57 +0000
Message-ID:  <E1wcl5Z-0008Qj-L2@lists.ubuntu.com>
Cc:  noreply+usn-bot@canonical.com

========================================================================== Ubuntu Security Notice USN-8471-1 June 25, 2026 containerd vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Several security issues were fixed in containerd. Software Description: - containerd: open and reliable container runtime library Details: It was discovered that containerd incorrectly handled HTTP/2 SETTINGS frames. A remote attacker could possibly use this issue to cause containerd to enter an infinite loop, resulting in a denial of service. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2026-33814) Jakub Ciolek and Kyle Elliott discovered that containerd incorrectly handled group parsing when creating containers from images. An attacker could possibly use this issue to cause containerd to consume excessive memory, resulting in a denial of service. (CVE-2026-47262) Robert Prast discovered that containerd incorrectly propagated labels from image configurations to containers. An attacker could possibly use this issue to execute arbitrary code on the host. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-53488) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS golang-github-containerd-containerd-api-dev 1.7.24~ds1-10ubuntu1+esm1 Available with Ubuntu Pro golang-github-containerd-containerd-dev 1.7.24~ds1-10ubuntu1+esm1 Available with Ubuntu Pro Ubuntu 24.04 LTS golang-github-containerd-containerd-dev 1.6.24~ds1-1ubuntu1.3+esm3 Available with Ubuntu Pro Ubuntu 22.04 LTS golang-github-containerd-containerd-dev 1.6.12-0ubuntu1~22.04.11 Ubuntu 20.04 LTS golang-github-containerd-containerd-dev 1.6.12-0ubuntu1~20.04.8+esm2 Available with Ubuntu Pro Ubuntu 18.04 LTS containerd 1.6.12-0ubuntu1~18.04.1+esm4 Available with Ubuntu Pro golang-github-containerd-containerd-dev 1.6.12-0ubuntu1~18.04.1+esm4 Available with Ubuntu Pro Ubuntu 16.04 LTS containerd 1.2.6-0ubuntu1~16.04.6+esm7 Available with Ubuntu Pro golang-github-docker-containerd-dev 1.2.6-0ubuntu1~16.04.6+esm7 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8471-1 CVE-2026-33814, CVE-2026-47262, CVE-2026-53488 Package Information: https://launchpad.net/ubuntu/+source/containerd/1.6.12-0u...


Attachment: signature.asc (type=application/pgp-signature)

-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmo9NwEACgkQcpJm3tlz hgGhLA/+LpoxVNLMCxXOjl/w0oTGrBWPx8MwjiDVe/Ntu889y7D0dnrS6MlAUJKX ZvtJWmW2+UyZev4MLkOBuLO49V3KjxGk7n1C30oMyjFjzyPmxd0M1KGuiC73RArj pvNdJ0U523HKnciutoBUqfodIjbHkpYhcS7pqmyYEbBQxOIG2susBx/0vACpYJvh 5MupfnRn0TJcmpHNBe2RTiQAdPc6rg8dLh9S+b61HECzbciE+oSqUA51QPi6WwjZ uZjsva83qL6AbE3/C2oXGTuUDY0qnzCSXhrzpZ2kmYKV8fmNlu4DFMY0vcPlX7Au bHToyfEKsmmmVm/puH8GXXOU4xBapVlArCRJh8Zr676OCqp5/cRDTSamZbkQAp0X h7I8V2zpsrye4DDB+8pkmFPVt1fCR1hoQIfq9s1bnTuYyNY5uSuqw0BJ9/4cZF2O Tqql+wkROFDmwNPUfp0uMTlaFWCsr6vZRxUGD9JHcQKSxOoVYJ35GkWkNBe8mfBa QF8TlTzY6JGZYSeOCezWABUHWL6Eq618RUpUksO933DOw+Gt8bHKKwgsLQQiA3rn 7oJVS1M4RWUgmmw3QDMV9pwyjo5GyEUxuiCutB7F0VRsVY67F2f8T0fSTkIVpkAF Ws6F4BLc8TuJujn+t42BHYVUyarPWypjkDZ+Z/dnSumL+rBRkPs= =petR -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds