Your message dated Wed, 16 Sep 2026 07:43:37 -0400
with message-id <[email protected]>
and subject line Bug#1141499: fixed in containerd 2.1.9+ds1-1
has caused the Debian Bug report #1141499,
regarding containerd: CVE-2026-46680
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1141499: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1141499
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: containerd
Version: 2.1.9+ds1-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Control: found -1 1.7.24~ds1-1
Hi,
The following vulnerability was published for containerd.
CVE-2026-46680[0]:
| containerd is an open-source container runtime. In versions prior to
| 1.7.32, 2.0.9, 2.2.4 and 2.3.1, containers launched with a numeric
| User directive that cannot be parsed as a 32-bit integer are
| incorrectly treated as a username, leading to runAsNonRoot evasion.
| If a crafted image provides an /etc/passwd file mapping this large
| numeric string to root, the container ultimately runs as root (UID
| 0). This allows the Kubernetes runAsNonRoot restriction to be
| bypassed, causing unexpected behavior for environments that require
| containers to run as a non-root user. This issue has been fixed in
| versions 1.7.32, 2.0.9, 2.2.4 and 2.3.1.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-46680
https://www.cve.org/CVERecord?id=CVE-2026-46680
[1]
https://github.com/containerd/containerd/security/advisories/GHSA-fqw6-gf59-qr4w
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: containerd
Version: 2.1.9+ds1-1
Found: 1.7.24~ds1-1
containerd in unstable/testing is not affected by CVE-2026-46680.
Upstream backported the fix for GHSA-fqw6-gf59-qr4w [1] (commit 2054cc54c,
PR #13497 [2]) to release/2.1, which was released in v2.1.8 and v2.1.9. Debian
packaged v2.1.9 as 2.1.9+ds1-1, so unstable is fine.
Closing with version 2.1.9+ds1-1 to update BTS version tracking for sid/forky.
The bug remains tracked for trixie/bookworm via the 1.7.24~ds1-1 found marker.
[1]
https://github.com/containerd/containerd/security/advisories/GHSA-fqw6-gf59-qr4w
[2] https://github.com/containerd/containerd/pull/13497
--- End Message ---