[ubuntu/jammy-security] containerd-app 2.2.1-0ubuntu1~22.04.2 (Accepted)

Eduardo Barretto eduardo.barretto at canonical.com
Thu Jun 25 11:09:45 UTC 2026


containerd-app (2.2.1-0ubuntu1~22.04.2) jammy-security; urgency=high

  * SECURITY UPDATE: HTTP/2 SETTINGS frame infinite loop (vendored
    golang.org/x/net)
    - debian/patches/CVE-2026-33814.patch: move s.Valid() check before
      switch in ForeachSetting callback
    - CVE-2026-33814
  * SECURITY UPDATE: Uncontrolled Resource Consumption via unbounded
    group parsing
    - debian/patches/CVE-2026-47262.patch: bound user-database file
      reads in openUserFile, reject non-regular files
    - CVE-2026-47262
  * SECURITY UPDATE: Insufficient Verification of Data Authenticity in
    CRI checkpoint import
    - debian/patches/CVE-2026-50195.patch: remove re-tagging of restored
      checkpoint base images
    - CVE-2026-50195
  * SECURITY UPDATE: Reserved label propagation from image configs
    - debian/patches/CVE-2026-53488.patch: filter containerd.io/ and
      io.cri-containerd labels from image config
    - CVE-2026-53488
  * SECURITY UPDATE: UNIX Symbolic Link Following in CRI checkpoint
    restore
    - debian/patches/CVE-2026-53489.patch: add copyNoFollow,
      checkpointArchiveEntryAllowed, assertCheckpointDirSafe; use
      dedicated restore subdirectory
    - CVE-2026-53489
  * SECURITY UPDATE: Improper Input Validation of CDI annotations in
    checkpoint restore
    - debian/patches/CVE-2026-53492.patch: filter cdi.k8s.io
      annotations on checkpoint restore
    - CVE-2026-53492

containerd-app (2.2.1-0ubuntu1~22.04.1) jammy; urgency=medium

  * New upstream version 2.2.1 (LP: #2127661)
  * d/containerd.docs: update notice file
  * d/copyright: update copyright data
  * d/rules: fix path of containerd commands
  * d/p/0001-Skip-test-failing-on-riscv64.patch: refresh patch
  * d/p/0002-Skip-tests-*-privileg.patch: refresh patch

containerd-app (1.7.30-0ubuntu1~22.04.1) jammy; urgency=medium

  * New upstream version 1.7.30
  * d/p/0001-Skip-test-failing-on-riscv64.patch: refresh patch
  * d/control: build with golang 1.24
  * d/rules: add golang 1.24 to PATH
  * d/copyright: update copyright data

containerd-app (1.7.28-0ubuntu1~22.04.1) jammy; urgency=medium

  * New upstream version 1.7.28 (LP: #2112523)
  * Build with Go 1.23.
    - d/control: b-d on golang-1.23-go instead of golang-1.22-go
    - d/rules: add Go 1.23 to $PATH

containerd-app (1.7.27-0ubuntu1~22.04.1) jammy; urgency=medium

  * New upstream version 1.7.27. (LP: #2085187)
  * d/p/CVE-2024-40635.patch: drop patch applied upstream

Date: 2026-06-24 07:03:12.037834+00:00
Changed-By: Eduardo Barretto <eduardo.barretto at canonical.com>
https://launchpad.net/ubuntu/+source/containerd-app/2.2.1-0ubuntu1~22.04.2
-------------- next part --------------
Sorry, changesfile not available.


More information about the jammy-changes mailing list