Skip to content

[release/2.3] vendor: golang.org/x/crypto v0.53.0#13608

Merged
AkihiroSuda merged 1 commit into
containerd:release/2.3from
thaJeztah:2.3_bump_crypto
Jun 18, 2026
Merged

[release/2.3] vendor: golang.org/x/crypto v0.53.0#13608
AkihiroSuda merged 1 commit into
containerd:release/2.3from
thaJeztah:2.3_bump_crypto

Conversation

@thaJeztah

Copy link
Copy Markdown
Member

Similar to 9838a32 on main;

golang.org/x/crypto < v0.52.0 contains various vulnerabilities; those do NOT impact containerd, but may show up as vulnerability in scanners;

=== Symbol Results ===

No vulnerabilities found.

=== Package Results ===

No other vulnerabilities found.

=== Module Results ===

Vulnerability #1: GO-2026-5033
    Invoking pathological inputs can lead to client panic in
    golang.org/x/crypto/ssh/agent
  More info: https://pkg.go.dev/vuln/GO-2026-5033
  Module: golang.org/x/crypto
    Found in: golang.org/x/[email protected]
    Fixed in: golang.org/x/[email protected]

Vulnerability #2: GO-2026-5023
    Invoking VerifiedPublicKeyCallback permissions skip enforcement in
    golang.org/x/crypto/ssh
  More info: https://pkg.go.dev/vuln/GO-2026-5023
  Module: golang.org/x/crypto
    Found in: golang.org/x/[email protected]
    Fixed in: golang.org/x/[email protected]

Vulnerability #3: GO-2026-5021
    Invoking auth bypass via unenforced @Revoked status in
    golang.org/x/crypto/ssh/knownhosts
  More info: https://pkg.go.dev/vuln/GO-2026-5021
  Module: golang.org/x/crypto
    Found in: golang.org/x/[email protected]
    Fixed in: golang.org/x/[email protected]

Vulnerability #4: GO-2026-5020
    Invoking infinite loop on large channel writes in golang.org/x/crypto/ssh
  More info: https://pkg.go.dev/vuln/GO-2026-5020
  Module: golang.org/x/crypto
    Found in: golang.org/x/[email protected]
    Fixed in: golang.org/x/[email protected]

Vulnerability #5: GO-2026-5019
    Invoking bypass of FIDO/U2F security keys physical interaction in
    golang.org/x/crypto/ssh
  More info: https://pkg.go.dev/vuln/GO-2026-5019
  Module: golang.org/x/crypto
    Found in: golang.org/x/[email protected]
    Fixed in: golang.org/x/[email protected]

Vulnerability #6: GO-2026-5018
    Invoking pathological RSA/DSA parameters may cause DoS in
    golang.org/x/crypto/ssh
  More info: https://pkg.go.dev/vuln/GO-2026-5018
  Module: golang.org/x/crypto
    Found in: golang.org/x/[email protected]
    Fixed in: golang.org/x/[email protected]

Vulnerability #7: GO-2026-5017
    Invoking client can cause server deadlock on unexpected responses in
    golang.org/x/crypto/ssh
  More info: https://pkg.go.dev/vuln/GO-2026-5017
  Module: golang.org/x/crypto
    Found in: golang.org/x/[email protected]
    Fixed in: golang.org/x/[email protected]

Vulnerability #8: GO-2026-5016
    Invoking memory leak when rejecting channels can lead to DoS in
    golang.org/x/crypto/ssh
  More info: https://pkg.go.dev/vuln/GO-2026-5016
  Module: golang.org/x/crypto
    Found in: golang.org/x/[email protected]
    Fixed in: golang.org/x/[email protected]

Vulnerability #9: GO-2026-5015
    Invoking server panic during CheckHostKey/Authenticate in
    golang.org/x/crypto/ssh
  More info: https://pkg.go.dev/vuln/GO-2026-5015
  Module: golang.org/x/crypto
    Found in: golang.org/x/[email protected]
    Fixed in: golang.org/x/[email protected]

Vulnerability #10: GO-2026-5014
    Invoking bypass of certificate restrictions in golang.org/x/crypto/ssh
  More info: https://pkg.go.dev/vuln/GO-2026-5014
  Module: golang.org/x/crypto
    Found in: golang.org/x/[email protected]
    Fixed in: golang.org/x/[email protected]

Vulnerability #11: GO-2026-5013
    Invoking byte arithmetic causes underflow and panic in
    golang.org/x/crypto/ssh
  More info: https://pkg.go.dev/vuln/GO-2026-5013
  Module: golang.org/x/crypto
    Found in: golang.org/x/[email protected]
    Fixed in: golang.org/x/[email protected]

Vulnerability #12: GO-2026-5006
    Invoking agent constraints dropped when forwarding keys in
    golang.org/x/crypto/ssh/agent
  More info: https://pkg.go.dev/vuln/GO-2026-5006
  Module: golang.org/x/crypto
    Found in: golang.org/x/[email protected]
    Fixed in: golang.org/x/[email protected]

Vulnerability #13: GO-2026-5005
    Invoking key constraints not enforced in golang.org/x/crypto/ssh/agent
  More info: https://pkg.go.dev/vuln/GO-2026-5005
  Module: golang.org/x/crypto
    Found in: golang.org/x/[email protected]
    Fixed in: golang.org/x/[email protected]

Your code is affected by 0 vulnerabilities.
This scan also found 0 vulnerabilities in packages you import and 13
vulnerabilities in modules you require, but your code doesn't appear to call
these vulnerabilities.

Similar to 9838a32 on main;

golang.org/x/crypto < v0.52.0 contains various vulnerabilities; those
do NOT impact containerd, but may show up as vulnerability in scanners;

    === Symbol Results ===

    No vulnerabilities found.

    === Package Results ===

    No other vulnerabilities found.

    === Module Results ===

    Vulnerability containerd#1: GO-2026-5033
        Invoking pathological inputs can lead to client panic in
        golang.org/x/crypto/ssh/agent
      More info: https://pkg.go.dev/vuln/GO-2026-5033
      Module: golang.org/x/crypto
        Found in: golang.org/x/[email protected]
        Fixed in: golang.org/x/[email protected]

    Vulnerability containerd#2: GO-2026-5023
        Invoking VerifiedPublicKeyCallback permissions skip enforcement in
        golang.org/x/crypto/ssh
      More info: https://pkg.go.dev/vuln/GO-2026-5023
      Module: golang.org/x/crypto
        Found in: golang.org/x/[email protected]
        Fixed in: golang.org/x/[email protected]

    Vulnerability containerd#3: GO-2026-5021
        Invoking auth bypass via unenforced @Revoked status in
        golang.org/x/crypto/ssh/knownhosts
      More info: https://pkg.go.dev/vuln/GO-2026-5021
      Module: golang.org/x/crypto
        Found in: golang.org/x/[email protected]
        Fixed in: golang.org/x/[email protected]

    Vulnerability containerd#4: GO-2026-5020
        Invoking infinite loop on large channel writes in golang.org/x/crypto/ssh
      More info: https://pkg.go.dev/vuln/GO-2026-5020
      Module: golang.org/x/crypto
        Found in: golang.org/x/[email protected]
        Fixed in: golang.org/x/[email protected]

    Vulnerability containerd#5: GO-2026-5019
        Invoking bypass of FIDO/U2F security keys physical interaction in
        golang.org/x/crypto/ssh
      More info: https://pkg.go.dev/vuln/GO-2026-5019
      Module: golang.org/x/crypto
        Found in: golang.org/x/[email protected]
        Fixed in: golang.org/x/[email protected]

    Vulnerability containerd#6: GO-2026-5018
        Invoking pathological RSA/DSA parameters may cause DoS in
        golang.org/x/crypto/ssh
      More info: https://pkg.go.dev/vuln/GO-2026-5018
      Module: golang.org/x/crypto
        Found in: golang.org/x/[email protected]
        Fixed in: golang.org/x/[email protected]

    Vulnerability containerd#7: GO-2026-5017
        Invoking client can cause server deadlock on unexpected responses in
        golang.org/x/crypto/ssh
      More info: https://pkg.go.dev/vuln/GO-2026-5017
      Module: golang.org/x/crypto
        Found in: golang.org/x/[email protected]
        Fixed in: golang.org/x/[email protected]

    Vulnerability containerd#8: GO-2026-5016
        Invoking memory leak when rejecting channels can lead to DoS in
        golang.org/x/crypto/ssh
      More info: https://pkg.go.dev/vuln/GO-2026-5016
      Module: golang.org/x/crypto
        Found in: golang.org/x/[email protected]
        Fixed in: golang.org/x/[email protected]

    Vulnerability containerd#9: GO-2026-5015
        Invoking server panic during CheckHostKey/Authenticate in
        golang.org/x/crypto/ssh
      More info: https://pkg.go.dev/vuln/GO-2026-5015
      Module: golang.org/x/crypto
        Found in: golang.org/x/[email protected]
        Fixed in: golang.org/x/[email protected]

    Vulnerability containerd#10: GO-2026-5014
        Invoking bypass of certificate restrictions in golang.org/x/crypto/ssh
      More info: https://pkg.go.dev/vuln/GO-2026-5014
      Module: golang.org/x/crypto
        Found in: golang.org/x/[email protected]
        Fixed in: golang.org/x/[email protected]

    Vulnerability containerd#11: GO-2026-5013
        Invoking byte arithmetic causes underflow and panic in
        golang.org/x/crypto/ssh
      More info: https://pkg.go.dev/vuln/GO-2026-5013
      Module: golang.org/x/crypto
        Found in: golang.org/x/[email protected]
        Fixed in: golang.org/x/[email protected]

    Vulnerability containerd#12: GO-2026-5006
        Invoking agent constraints dropped when forwarding keys in
        golang.org/x/crypto/ssh/agent
      More info: https://pkg.go.dev/vuln/GO-2026-5006
      Module: golang.org/x/crypto
        Found in: golang.org/x/[email protected]
        Fixed in: golang.org/x/[email protected]

    Vulnerability containerd#13: GO-2026-5005
        Invoking key constraints not enforced in golang.org/x/crypto/ssh/agent
      More info: https://pkg.go.dev/vuln/GO-2026-5005
      Module: golang.org/x/crypto
        Found in: golang.org/x/[email protected]
        Fixed in: golang.org/x/[email protected]

    Your code is affected by 0 vulnerabilities.
    This scan also found 0 vulnerabilities in packages you import and 13
    vulnerabilities in modules you require, but your code doesn't appear to call
    these vulnerabilities.

Signed-off-by: Sebastiaan van Stijn <[email protected]>
@thaJeztah
thaJeztah requested a review from AkihiroSuda June 18, 2026 11:18
@github-project-automation github-project-automation Bot moved this from Needs Triage to Review In Progress in Pull Request Review Jun 18, 2026
@AkihiroSuda
AkihiroSuda merged commit b54e3ec into containerd:release/2.3 Jun 18, 2026
87 of 90 checks passed
@github-project-automation github-project-automation Bot moved this from Review In Progress to Done in Pull Request Review Jun 18, 2026
@thaJeztah
thaJeztah deleted the 2.3_bump_crypto branch June 18, 2026 12:01
jaredledvina added a commit to DataDog/containerd that referenced this pull request Jul 7, 2026
containerd 2.3.2

Welcome to the v2.3.2 release of containerd!

The second patch release for containerd 2.3 contains various fixes
and updates including security patches.

* **containerd**
  * [**CVE-2026-50195**](GHSA-cvxm-645q-p574)
  * [**CVE-2026-53488**](GHSA-xhf5-7wjv-pqxp)
  * [**CVE-2026-53492**](GHSA-33vj-92qq-66hc)
  * [**CVE-2026-53489**](GHSA-rgh6-rfwx-v388)
  * [**CVE-2026-47262**](GHSA-jpcc-p29g-p8mq)

* Fix a data race when reading shim logs on Windows ([containerd#13522](containerd#13522))

* Allow the last host to retry on transient network errors ([containerd#13591](containerd#13591))

* Fix container startup failures caused by concurrent task RPC timeouts during slow container creation ([containerd#13512](containerd#13512))

Please try out the release binaries and report any issues at
https://github.com/containerd/containerd/issues.

* Samuel Karp
* Chris Henzie
* Akihiro Suda
* Derek McGowan
* Akhil Mohan
* Austin Vazquez
* Ben Cressey
* Brian Goff
* Maksym Pavlenko
* Sebastiaan van Stijn
* Sergey Kanzhelev

<details><summary>30 commits</summary>
<p>

* Prepare release notes for v2.3.2 ([containerd#13627](containerd#13627))
  * [`fb8ca00b0`](containerd@fb8ca00) Prepare release notes for v2.3.2
  * [`9c69960ba`](containerd@9c69960) Merge commit from fork
  * [`0f6251520`](containerd@0f62515) Merge commit from fork
  * [`91d7471e2`](containerd@91d7471) cri: filter CDI annotations on checkpoint restore
  * [`7c2e086bf`](containerd@7c2e086) Merge commit from fork
  * [`dae67765f`](containerd@dae6776) cri: do not re-tag restored checkpoints
  * [`94aa1e2c1`](containerd@94aa1e2) Merge commit from fork
  * [`09599078f`](containerd@0959907) cri: make checkpoint restore robust to unexpected archive content
  * [`e1fdb8d22`](containerd@e1fdb8d) Merge commit from fork
  * [`ff1d116ef`](containerd@ff1d116) Bound user-database file reads in openUserFile
  * [`d156e07cb`](containerd@d156e07) Merge commit from fork
  * [`f99aad54a`](containerd@f99aad5) Do not propagate reserved labels from image configs
* vendor: golang.org/x/crypto v0.53.0 ([containerd#13608](containerd#13608))
  * [`0b9469501`](containerd@0b94695) [release/2.3] vendor: golang.org/x/crypto v0.53.0
* resolver: retry on transient network errors ([containerd#13591](containerd#13591))
  * [`983bbddc1`](containerd@983bbdd) resolver: retry on transient network errors
* update runc binary to v1.4.3 ([containerd#13601](containerd#13601))
  * [`3f76f2dc1`](containerd@3f76f2d) update runc binary to v1.4.3
* update go to 1.26.4 ([containerd#13580](containerd#13580))
  * [`8a49dfe85`](containerd@8a49dfe) update go to 1.26.4
  * [`5aa6bb2b7`](containerd@5aa6bb2) remove 1.26.2 from CI builds as it is not supported any longer due to the dependency
* Configure udevd children-max for root-test ([containerd#13568](containerd#13568))
  * [`bfb8aebc0`](containerd@bfb8aeb) Configure udevd children-max for root-test
* core/runtime/v2: fix race on Windows deferredPipeConnection.c in Read ([containerd#13522](containerd#13522))
  * [`62ceafff0`](containerd@62ceaff) core/runtime/v2: fix race on Windows deferredPipeConnection.c in Read
* runc-shim: don't hold the service lock across runc create ([containerd#13512](containerd#13512))
  * [`9b0c0dc58`](containerd@9b0c0dc) runc-shim: don't hold the service lock across runc create
* contrib/checkpoint: increase timeouts to 30s ([containerd#13459](containerd#13459))
  * [`f588bc6fb`](containerd@f588bc6) contrib/checkpoint: increase timeouts to 30s
</p>
</details>

* **golang.org/x/crypto**  v0.49.0 -> v0.53.0
* **golang.org/x/mod**     v0.35.0 -> v0.36.0
* **golang.org/x/net**     v0.52.0 -> v0.55.0
* **golang.org/x/sync**    v0.20.0 -> v0.21.0
* **golang.org/x/sys**     v0.43.0 -> v0.46.0
* **golang.org/x/term**    v0.41.0 -> v0.44.0
* **golang.org/x/text**    v0.35.0 -> v0.38.0

Previous release can be found at [v2.3.1](https://github.com/containerd/containerd/releases/tag/v2.3.1)
* `containerd-<VERSION>-<OS>-<ARCH>.tar.gz`:         ✅Recommended. Dynamically linked with glibc 2.35 (Ubuntu 22.04).
* `containerd-static-<VERSION>-<OS>-<ARCH>.tar.gz`:  Statically linked. Expected to be used on Linux distributions that do not use glibc >= 2.35. Not position-independent.

In addition to containerd, typically you will have to install [runc](https://github.com/opencontainers/runc/releases)
and [CNI plugins](https://github.com/containernetworking/plugins/releases) from their official sites too.

See also the [Getting Started](https://github.com/containerd/containerd/blob/main/docs/getting-started.md) documentation.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

Archived in project

Development

Successfully merging this pull request may close these issues.

4 participants