—
GO-2026-6444
containerd: CRI ExecSync Goroutine Leak Leads to Node-Level Denial of Service in github.com/containerd/containerd
Quick fix
GO-2026-6444 — github.com/containerd/containerd: upgrade to the fixed version with the command below.
go get github.com/containerd/containerd@v1.7.35Details
containerd: CRI ExecSync Goroutine Leak Leads to Node-Level Denial of Service in github.com/containerd/containerd
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/containerd/containerd
Introduced in:
0Fixed in: 1.7.35Fix
go get github.com/containerd/containerd@v1.7.35Go/github.com/containerd/containerd/v2
Introduced in:
0Fixed in: 2.0.12Fix
go get github.com/containerd/containerd/v2@v2.0.12References
- https://github.com/containerd/containerd/security/advisories/GHSA-7jxh-36q5-gcqv[ADVISORY]
- https://github.com/containerd/containerd/releases/tag/v1.7.35[WEB]
- https://github.com/containerd/containerd/releases/tag/v2.0.12[WEB]
- https://github.com/containerd/containerd/releases/tag/v2.2.8[WEB]
- https://github.com/containerd/containerd/releases/tag/v2.3.5[WEB]