Skip to content

fix: update containerd versions on Ubuntu to fix CVEs#8595

Merged
djsly merged 1 commit into
mainfrom
nishp/update/cilium
May 27, 2026
Merged

fix: update containerd versions on Ubuntu to fix CVEs#8595
djsly merged 1 commit into
mainfrom
nishp/update/cilium

Conversation

@awesomenix
Copy link
Copy Markdown
Contributor

Fixes bunch of CVE

Copilot AI review requested due to automatic review settings May 27, 2026 05:49
@github-actions github-actions Bot added the components This pull request updates cached components on Linux or Windows VHDs label May 27, 2026
Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the pinned containerd (moby-containerd) package versions in parts/common/components.json, which is used to drive VHD component selection and expected package versions across OS variants.

Changes:

  • Bump Ubuntu 24.04 moby-containerd from 2.1.6-ubuntu24.04u22.1.7-ubuntu24.04u2
  • Bump Ubuntu 22.04 moby-containerd from 1.7.31-ubuntu22.04u11.7.32-ubuntu22.04u1
  • Bump Ubuntu 20.04 moby-containerd from 1.7.30-ubuntu20.04u41.7.32-ubuntu20.04u1

Package Update Analysis: containerd (moby-containerd)

Version change:

  • Ubuntu 24.04: 2.1.6-ubuntu24.04u22.1.7-ubuntu24.04u2 (patch update)
  • Ubuntu 22.04: 1.7.31-ubuntu22.04u11.7.32-ubuntu22.04u1 (patch update)
  • Ubuntu 20.04: 1.7.30-ubuntu20.04u41.7.32-ubuntu20.04u1 (patch update)

OS variants affected: Ubuntu 20.04, Ubuntu 22.04, Ubuntu 24.04
OS variants NOT updated: Mariner 2.0, Azure Linux 3.0, Windows (containerd)

Changes between versions

Upstream changelog not found in-repo for these specific distro/package revision variants. Manual validation (package availability + e2e/VHD build validation) recommended before merge.

Overall Risk: 🟡 Medium

Justification: Container runtime updates are high-impact even when patch-level; additionally, the PR description/title implies a broad CVE fix while only Ubuntu variants are updated.
Recommendation: Request changes/clarification and ensure OS coverage matches the stated CVE scope.

Comment thread parts/common/components.json
Comment thread parts/common/components.json
@djsly djsly changed the title fix: update containerd versions to fix CVE fix: update containerd versions on Ubuntu to fix CVEs May 27, 2026
@djsly djsly merged commit 79e5d72 into main May 27, 2026
42 of 44 checks passed
@djsly djsly deleted the nishp/update/cilium branch May 27, 2026 13:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

components This pull request updates cached components on Linux or Windows VHDs

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants