NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #265 by repository stars
Last release 2 days ago
06 Oct 2026
Ships on a steady schedule
a new release about every 9 days
Most releases are documented
notes for 44 of 55 stable releases
Nothing withdrawn
no release was ever pulled
13 years old
7470 releases · first in 2014
Nothing published for this version
It contains a couple of new features, but is mostly made up of various cleanups (such as the removal of many deprecated APIs) and improvements.
This is the first release candidate of the upcoming runc 1.6.0 release.
It contains a couple of new features, but is mostly made up of various
cleanups (such as the removal of many deprecated APIs) and improvements.
This version includes all of the patches backported to runc v1.5.2.
Users are strongly encouraged to test our release candidates so we can
fix issues before the general release.
configs.ToCPUSet now returns a unix.CPUSetDynamic instead of a*unix.CPUSet, and the Initial/Final fields of configs.CPUAffinity andNodes field of configs.LinuxMemoryPolicy have changed typelibcontainer/devices package has been removed. Usegithub.com/moby/sys/devices instead. (#5142, #5223, #5495)RecvFile, SendFile, and SendRawFd functions have beenlibcontainer/utils. (#5227, #5231, #5495)EXTRA_BUILDTAGS make variable has been removed, and settingRUNC_BUILDTAGS instead. (#5171, #5198, #5511)process.user.umask is now honored for a container which does not have itsno such file or directory error about a procfs file. (#5438, #5441)urfave_cli_no_template build tag,cpuAffinity and NUMA memoryPolicy settings are no longer limitedroot.readonly), a read-only tmpfs mount, or a read-only /dev, but doesmaskedPaths andreadonlyPaths, which have the same requirement, were already treated.urfave_cli_no_docs build tag is no longer used. (#5184)runc start now waits for the container's init process using poll(2) andThe runc binaries distributed with this release are statically linked with
the following GNU LGPL-2.1 licensed libraries, with runc acting
as a "work that uses the Library":
Similarly, the runc binaries distributed with this release are also
statically linked with the following MPLv2 licensed libraries,
with runc acting as a "Larger Work":
The versions of these libraries were not modified from their upstream versions,
but in order to comply with their corresponding licenses, we have attached the
complete source code for those libraries which (when combined with the attached
runc source code) may be used to exercise your rights under their respective
licenses.
However, we strongly suggest that you make use of your distribution's packages
or download them from the authoritative upstream sources, especially since
these libraries are related to the security of your containers.
Thanks to the following contributors who made this release possible:
Signed-off-by: Kir Kolyshkin kolyshkin@gmail.com
One column per quarter.
runc v1.6.0-rc.1 -- "Lo bueno, si breve, dos veces bueno." Pre-release
Pre-release
Compare
Note that using --cgroup requires the same privileges as running runc exec itself, so this is a correctness rather than a security fix. ( #5403 , #545…
This is the second patch release in the 1.5.z release series of runc,
which primarily includes a workaround for a Linux kernel bug causing
random runc crashes when using cgroup v2, and other fixes.
runc exec -p with a process.json lacking env now sets HOME againrunc exec --cgroup (and the equivalent libcontainer Process.SubCgroupPaths--cgroup requires the same privileges as running runc exec itself, soO_CLOEXEC when opening the cgroup v2 directory to set uprootfsPropagation is set to rslave, the rootfs parent mount is no0 0 4294967295), asPrivateUsers=full. Previously this madebpf_prog_query(BPF_CGROUP_DEVICE) failed: operation not permitted.runc init panic (SIGABRT) on the error path, caused by SELinuxSECCOMP_FILTER_FLAG_WAIT_KILLABLE_RECV workaround added in-g -O2 CFLAGS); previously it wasThe runc binaries distributed with this release are statically linked with
the following GNU LGPL-2.1 licensed libraries, with runc acting
as a "work that uses the Library":
Similarly, the runc binaries distributed with this release are also
statically linked with the following MPLv2 licensed libraries,
with runc acting as a "Larger Work":
The versions of these libraries were not modified from their upstream versions,
but in order to comply with their corresponding licenses, we have attached the
complete source code for those libraries which (when combined with the attached
runc source code) may be used to exercise your rights under their respective
licenses.
However, we strongly suggest that you make use of your distribution's packages
or download them from the authoritative upstream sources, especially since
these libraries are related to the security of your containers.
Thanks to the following contributors who made this release possible:
Signed-off-by: Kir Kolyshkin kolyshkin@gmail.com
runc v1.5.2 -- "Всё сбудется, стоит только расхотеть!" Latest
Latest
Compare
This is the first patch release in the 1.5.z release series of runc, and primarily includes a fix for a serious regression on Ubuntu 20.04 kernels.
This is the first patch release in the 1.5.z release series of runc, and
primarily includes a fix for a serious regression on Ubuntu 20.04
kernels.
maskPaths optimisation added intmpfs withnr_inodes=1 option will fail due to a downstream kernel patchnr_inodes=2 instead if the operation fails. (#5348, #5358, #5359)EINVAL for seccomp SECCOMP_FILTER_FLAG_WAIT_KILLABLE_RECVThe runc binaries distributed with this release are statically linked with
the following GNU LGPL-2.1 licensed libraries, with runc acting
as a "work that uses the Library":
Similarly, the runc binaries distributed with this release are also
statically linked with the following MPLv2 licensed libraries,
with runc acting as a "Larger Work":
The versions of these libraries were not modified from their upstream versions,
but in order to comply with their corresponding licenses, we have attached the
complete source code for those libraries which (when combined with the attached
runc source code) may be used to exercise your rights under their respective
licenses.
However, we strongly suggest that you make use of your distribution's packages
or download them from the authoritative upstream sources, especially since
these libraries are related to the security of your containers.
Thanks to the following contributors who made this release possible:
Signed-off-by: Aleksa Sarai cyphar@cyphar.com
El lujo es vulgaridad, dijo, y me conquistó.
maskPaths optimisation added in
1.5.0-rc.3 (#5275). On Ubuntu Focal (20.04), attempts to mount tmpfs with
the nr_inodes=1 option will fail due to a downstream kernel patch
(ironically originating from AUFS). We now have a fallback path using
nr_inodes=2 instead if the operation fails. (#5348, #5358, #5359)EINVAL for seccomp SECCOMP_FILTER_FLAG_WAIT_KILLABLE_RECV
when trying to rewrite the filter. This appears to only happen if you compile
runc with libseccomp >= 2.6.0 and then run it with an < 2.6.0 libseccomp.
(#5347, #5354)runc v1.5.1 -- "El lujo es vulgaridad, dijo, y me conquistó."
Compare
This is the somewhat-delayed^Wlong-awaited first stable release of the 1.5.z release branch of runc. It contains a handful of fixes for issues found i
This is the somewhat-delayed^Wlong-awaited first stable release of the
1.5.z release branch of runc. It contains a handful of fixes for issues
found in 1.5.0-rc.3 and an important dependency bump for libpathrs.
This is the third release of runc following our new release and support
policy (see RELEASES.md for more details). This means that, as of this
release:
runc version and runc features now provide version information aboutlibpathrs build tag). (#5291, #5328)org.opencontainers.runc.version annotation includedrunc features contained an extraneous \n, possibly causing issues withlibpathrs build tag) now depends on libpathrsThe runc binaries distributed with this release are statically linked with
the following GNU LGPL-2.1 licensed libraries, with runc acting
as a "work that uses the Library":
Similarly, the runc binaries distributed with this release are also
statically linked with the following MPLv2 licensed libraries,
with runc acting as a "Larger Work":
The versions of these libraries were not modified from their upstream versions,
but in order to comply with their corresponding licenses, we have attached the
complete source code for those libraries which (when combined with the attached
runc source code) may be used to exercise your rights under their respective
licenses.
However, we strongly suggest that you make use of your distribution's packages
or download them from the authoritative upstream sources, especially since
these libraries are related to the security of your containers.
Thanks to the following contributors who made this release possible:
Signed-off-by: Aleksa Sarai cyphar@cyphar.com
runc v1.5.0 -- "Why do we even have that lever?!"
Compare
Among some performance improvements and bugfixes, it includes a fix for a low-severity vulnerability ( CVE-2026-41579 ) and users are encouraged to up…
This is the third release candidate for the 1.5.z series of runc. Among
some performance improvements and bugfixes, it includes a fix for a
low-severity vulnerability (CVE-2026-41579) and users are encouraged to
update. As it was a low-severity vulnerability and it was reported by
multiple people, we decided to release it publicly with NO EMBARGO.
We plan to release 1.5.0 in the next two weeks.
This release includes a fix for the following low-severity security issue:
/dev symlink to havecmsg helpers from github.com/opencontainers/runc/libcontainer/utils//go:fix inline to ease migration for libcontainer/devices symbolsrunc list now correctly handles non-existant --root arguments. (#5297,maskPaths, runc will now re-use a singletmpfs instance (which is not writable) to reduce the number tmpfsThe runc binaries distributed with this release are statically linked with
the following GNU LGPL-2.1 licensed libraries, with runc acting
as a "work that uses the Library":
Similarly, the runc binaries distributed with this release are also
statically linked with the following MPLv2 licensed libraries,
with runc acting as a "Larger Work":
The versions of these libraries were not modified from their upstream versions,
but in order to comply with their corresponding licenses, we have attached the
complete source code for those libraries which (when combined with the attached
runc source code) may be used to exercise your rights under their respective
licenses.
However, we strongly suggest that you make use of your distribution's packages
or download them from the authoritative upstream sources, especially since
these libraries are related to the security of your containers.
Thanks to the following contributors for making this release possible:
Signed-off-by: Aleksa Sarai cyphar@cyphar.com
The best way to get a drink out of a Vogon is to stick your finger down his throat.
This release includes a fix for the following low-severity security issue:
/dev symlink to have
limited write access to the host filesystem in ways that our analysis
indicates was too limited to be problematic in practice. This bug was very
similar to those fixed in [CVE-2025-31133][], [CVE-2025-52565][],
[CVE-2025-31133][] and was simply missed at the time when we hardened the
rootfs preparation code. We have conducted a deeper audit and not found any
other problematic cases.cmsg helpers from github.com/opencontainers/runc/libcontainer/utils
have been moved to an internal package. We have included wrapper functions
but they will be removed in runc 1.6. (#5227, #5231)//go:fix inline to ease migration for libcontainer/devices symbols
that are deprecated and scheduled for removal in runc 1.6. (#5223, #5225)runc list now correctly handles non-existent --root arguments. (#5297,
#5301)maskPaths, runc will now reuse a single
tmpfs instance (which is not writeable) to reduce the number tmpfs
superblocks that need to be reaped when containers die (in particular,
Kubernetes applies masks to per-CPU sysfs directories which get expensive
quickly). (#5275, #5280)runc 1.5.0-rc.3 -- "The best way to get a drink out of a Vogon is to stick your finger down his throat." Pre-release
Pre-release
Compare
Nothing published for this version
…runc 1.3.z will only receive high-severity security fixes for 6 months and runc 1.2.z will become unmaintained -- users are thus very strongly encoura…
This is the second release candidate of the runc 1.5.0 release. It
mostly contains build fixes and improvements, but also includes
a new minor feature and some deprecations.
runc v1.5.0-rc.2 includes all of the patches backported to runc v1.4.2.
Users are strongly encouraged to test our release candidates over the
next few weeks so we can fix issues before the general release. You
should expect runc 1.5.0 to be released at the end of April 2026 (at
which point, runc 1.3.z will only receive high-severity security fixes
for 6 months and runc 1.2.z will become unmaintained -- users are thus
very strongly encouraged to migrate to a newer version).
RUNC_BUILDTAGS make or shell environment variable can-). (#5198, #5171)EXTRA_BUILDTAGS make variable is deprecated in favor of RUNC_BUILDTAGSlibcontainer/devices has been deprecated in favour ofgithub.com/moby/sys/devices (which is a carbon copy of the package). ItThe runc binaries distributed with this release are statically linked with
the following GNU LGPL-2.1 licensed libraries, with runc acting
as a "work that uses the Library":
Similarly, the runc binaries distributed with this release are also
statically linked with the following MPLv2 licensed libraries,
with runc acting as a "Larger Work":
The versions of these libraries were not modified from their upstream versions,
but in order to comply with their corresponding licenses, we have attached the
complete source code for those libraries which (when combined with the attached
runc source code) may be used to exercise your rights under their respective
licenses.
However, we strongly suggest that you make use of your distribution's packages
or download them from the authoritative upstream sources, especially since
these libraries are related to the security of your containers.
Thanks to the following contributors for making this release possible:
Signed-off-by: Kir Kolyshkin kolyshkin@gmail.com
runc v1.5.0-rc.2 -- "いざやいざや、見に行かん" Pre-release
Pre-release
Compare
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →