NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #265 by repository stars
Last release 3 days ago
03 Oct 2026
Ships on a steady schedule
a new release about every 9 days
Most releases are documented
notes for 44 of 55 stable releases
Nothing withdrawn
no release was ever pulled
13 years old
7464 releases · first in 2014
Nothing published for this version
Nothing published for this version
Nothing published for this version
One column per quarter.
…runc 1.3.z will only receive high-severity security fixes for 6 months and runc 1.2.z will become unmaintained -- users are thus very strongly encoura…
This is the first release candidate of the runc 1.5.0 release. It
contains a couple of new features, but is mostly made up of various
cleanups (such as the removal of many deprecated APIs) and improvements.
runc v1.5.0-rc.1 includes all of the patches backported to runc v1.4.1.
Users are strongly encouraged to test our release candidates over the
next two months so we can fix issues before the general release. You
should expect runc 1.5.0 to be released at the end of April 2026 (at
which point, runc 1.3.z will only receive high-severity security fixes
for 6 months and runc 1.2.z will become unmaintained -- users are thus
very strongly encouraged to migrate to a newer version).
CleanPath, StripRoot, and WithProcfd from libcontainer/utils. NoteWithProcfdFile has not been removed (due to import cycle issues) butlibcontainer/configsgithub.com/opencontainers/cgroups (#5141):
libcontainer/configs.Cgrouplibcontainer/configs.Resourceslibcontainer/configs.FreezerStatelibcontainer/configs.LinuxRdmalibcontainer/configs.BlockIODevicelibcontainer/configs.WeightDevicelibcontainer/configs.ThrottleDevicelibcontainer/configs.HugepageLimitlibcontainer/configs.IfPrioMaplibcontainer/configs.Undefinedlibcontainer/configs.Frozenlibcontainer/configs.Thawedlibcontainer/configs.NewWeightDevicelibcontainer/configs.NewThrottleDevicelibcontainer/configs.HookList.RunHooks. (#5141)libcontainer/configs.MPOL_* (#5141)libcontainer/devices which are now maintained ingithub.com/opencontainers/cgroups/devices/config (#5141):
libcontainer/devices.Wildcardlibcontainer/devices.WildcardDevicelibcontainer/devices.BlockDevicelibcontainer/devices.CharDevicelibcontainer/devices.FifoDevicelibcontainer/devices.Devicelibcontainer/devices.Permissionslibcontainer/devices.Typelibcontainer/devices.Rulelibcontainer.Process methods (Wait, Pid, Signal) andlibcontainer/configs.Config methods (HostUID, HostRootUID, HostGID,HostRootGID) now use pointer receivers. (#5088)libcontainer has been moved out of a README and intoExample* test file that will be compile-tested by our CI. Aslibcontainer API directly. (#5127)libcontainer/configs.Mount.Relabel configuration field (used to relabelz and Z "pseudo" mount options) was never accessiblememfd-bind helper binary has been removed, as it has never been/proc/self/exe sealing we introduced in runc 1.2.0. (#5141)user.* sysctls. (#4889)libpathrs build tag), but we currentlyrunc exec will now request systemd to move the exec process into therunc init have historically been quite painful to understandrunc-$version.tar.xz to make distroThe runc binaries distributed with this release are statically linked with
the following GNU LGPL-2.1 licensed libraries, with runc acting
as a "work that uses the Library":
Similarly, the runc binaries distributed with this release are also
statically linked with the following MPLv2 licensed libraries,
with runc acting as a "Larger Work":
The versions of these libraries were not modified from their upstream versions,
but in order to comply with their corresponding licenses, we have attached the
complete source code for those libraries which (when combined with the attached
runc source code) may be used to exercise your rights under their respective
licenses.
However, we strongly suggest that you make use of your distribution's packages
or download them from the authoritative upstream sources, especially since
these libraries are related to the security of your containers.
Thanks to the following contributors for making this release possible:
Signed-off-by: Aleksa Sarai cyphar@cyphar.com
runc v1.5.0-rc.1 -- "憎しみを束ねてもそれは脆い!" Pre-release
Pre-release
Compare
Among some performance improvements and bugfixes, it includes a fix for a low-severity vulnerability ( CVE-2026-41579 ) and users are encouraged to up…
This is the third patch release of the 1.4.z series of runc. Among some
performance improvements and bugfixes, it includes a fix for a
low-severity vulnerability (CVE-2026-41579) and users are encouraged to
update. As it was a low-severity vulnerability and it was reported by
multiple people, we decided to release it publicly with NO EMBARGO.
This release includes a fix for the following low-severity security issue:
/dev symlink to havemaskPaths, runc will now re-use a singletmpfs instance (which is not writable) to reduce the number tmpfsThe runc binary distributed with this release are statically linked with
the following GNU LGPL-2.1 licensed libraries, with runc acting
as a "work that uses the Library":
The versions of these libraries were not modified from their upstream versions,
but in order to comply with the LGPL-2.1 (§6(a)), we have attached the
complete source code for those libraries which (when combined with the attached
runc source code) may be used to exercise your rights under the LGPL-2.1.
However we strongly suggest that you make use of your distribution's packages
or download them from the authoritative upstream sources, especially since
these libraries are related to the security of your containers.
Thanks to the following contributors for making this release possible:
Signed-off-by: Aleksa Sarai cyphar@cyphar.com
The best way to irritate him is to feed his grandmother to the Ravenous Bugblatter Beast of Traal.
This release includes a fix for the following low-severity security issue:
/dev symlink to have
limited write access to the host filesystem in ways that our analysis
indicates was too limited to be problematic in practice. This bug was very
similar to those fixed in [CVE-2025-31133][], [CVE-2025-52565][],
[CVE-2025-31133][] and was simply missed at the time when we hardened the
rootfs preparation code. We have conducted a deeper audit and not found any
other problematic cases.maskPaths, runc will now reuse a single
tmpfs instance (which is not writable) to reduce the number tmpfs
superblocks that need to be reaped when containers die (in particular,
Kubernetes applies masks to per-CPU sysfs directories which get expensive
quickly). (#5275, #5281)runc 1.4.3 -- "The best way to irritate him is to feed his grandmother to the Ravenous Bugblatter Beast of Traal."
Compare
This is the second patch release of the 1.4.z release series of runc.
This is the second patch release of the 1.4.z release series of runc.
A regression in runc v1.3.0 which can result in a stuck runc exec or
runc run when the container process runs for a short time. (#5208,
#5210, #5216)
Mount sources that need to be open on the host are now closed earlier during
container start, reducing the total amount of used file descriptors and
helping to avoid hitting the open files limit when handling many such mounts.
(#5177, #5201)
The runc binary distributed with this release are statically linked with
the following GNU LGPL-2.1 licensed libraries, with runc acting
as a "work that uses the Library":
The versions of these libraries were not modified from their upstream versions,
but in order to comply with the LGPL-2.1 (§6(a)), we have attached the
complete source code for those libraries which (when combined with the attached
runc source code) may be used to exercise your rights under the LGPL-2.1.
However we strongly suggest that you make use of your distribution's packages
or download them from the authoritative upstream sources, especially since
these libraries are related to the security of your containers.
Thanks to the following contributors for making this release possible:
Signed-off-by: Kir Kolyshkin kolyshkin@gmail.com
runc v1.4.2 -- "Я — Земля! Я своих провожаю питомцев"
Compare
This is the first patch release of the 1.4.z release series of runc. It primarily includes some fixes for issues found in 1.4.0.
This is the first patch release of the 1.4.z release series of runc.
It primarily includes some fixes for issues found in 1.4.0.
initSystemdProps when processing certain systemdcrypto/tls dependency by open-coding the systemd socketos.Is* error usage, improving error type detection to makeos/exec.Cmd which causedCLONE_INTO_CGROUP (on newer kernels). This has nowatime-related mount flags (rrelatime et al.) are now appliedrunc exec due to CLONE_INTO_CGROUP in the/sys/fs/cgroup mounted rw. (#5117, #5101)cannot start a container that has stopped errors when runningrunc create and has thus been reverted. (#5157, #5153, #5151, #4645, #4757)runc.armhf release binaries worklibseccomp within a Debian container and statically link toarmhfThe runc binary distributed with this release are statically linked with
the following GNU LGPL-2.1 licensed libraries, with runc acting
as a "work that uses the Library":
The versions of these libraries were not modified from their upstream versions,
but in order to comply with the LGPL-2.1 (§6(a)), we have attached the
complete source code for those libraries which (when combined with the attached
runc source code) may be used to exercise your rights under the LGPL-2.1.
However we strongly suggest that you make use of your distribution's packages
or download them from the authoritative upstream sources, especially since
these libraries are related to the security of your containers.
Thanks to the following contributors for making this release possible:
runc v1.4.1 -- "La guerre n'est pas une aventure. La guerre est une maladie. Comme le typhus."
Compare
This fixes a regression introduced in our [CVE-2025-52881][] mitigation patches. (#4971, #4973, #4976)
路漫漫其修远兮,吾将上下而求索!
CleanPath, StripRoot, WithProcfd, and WithProcfdFile from
libcontainer/utils. (#4985)pids.limit has been updated to match the newer guidance
from the OCI runtime specification. In particular, now a maximum limit value
of 0 will be treated as an actual limit (due to limitations with systemd,
it will be treated the same as a limit value of 1). We only expect users
that explicitly set pids.limit to 0 will see a behaviour change.
(opencontainers/cgroups#48, #4949)cpuacct.usage_all resilience when parsing data from
patched kernels (such as the Tencent kernels). (opencontainers/cgroups#46,
opencontainers/cgroups#50)prepareCgroupFD error. (#4936)tmpfs mount, only set the mode= argument if the target
path already existed. This fixes a regression introduced in our
CVE-2025-52881 mitigation patches. (#4971, #4973, #4976)pathrs
helper functions, which should ensure we will not regress dangling symlink
users. (#4985)(*CPUSet).Fill. (#4927)runc init have historically been quite painful to understand
and debug, we have made several improvements to make them more comprehensive
and thus useful when debugging issues. (#5040, #4951, #4928)Nothing published for this version
[CVE-2025-31133][] exploits an issue with how masked paths are implemented in runc. When masking files, runc will bind-mount the container's /dev/null…
その日、人類は思い出した。
This release includes fixes for the following high-severity security issues:
CVE-2025-31133 exploits an issue with how masked paths are implemented in
runc. When masking files, runc will bind-mount the container's /dev/null
inode on top of the file. However, if an attacker can replace /dev/null
with a symlink to some other procfs file, runc will instead bind-mount the
symlink target read-write. This issue affected all known runc versions.
CVE-2025-52565 is very similar in concept and application to
CVE-2025-31133, except that it exploits a flaw in /dev/console
bind-mounts. When creating the /dev/console bind-mount (to /dev/pts/$n),
if an attacker replaces /dev/pts/$n with a symlink then runc will
bind-mount the symlink target over /dev/console. This issue affected all
versions of runc >= 1.0.0-rc3.
CVE-2025-52881 is a more sophisticated variant of CVE-2019-19921, which was a flaw that allowed an attacker to trick runc into writing the LSM process labels for a container process into a dummy tmpfs file and thus not apply the correct LSM labels to the container process. The mitigation we applied for CVE-2019-19921 was fairly limited and effectively only caused runc to verify that when we write LSM labels that those labels are actual procfs files. This issue affects all known runc versions.
(*CPUSet).Fill rather than our hacky optimisation when
resetting the CPU affinity of runc. (#4926, #4927)(*setns).start if an error occurs.
(#4930, #4936)The deprecated libcontainer/userns package has been removed; use github.com/moby/sys/userns instead. (#4910, #4911)
私の役目は信じるかどうかではない。行うかどうかだ。
libcontainer/userns package has been removed; use
github.com/moby/sys/userns instead. (#4910, #4911)user.* sysctls for user-namespaced containers, as they are
namespaced and thus safe to configure. (#4889, #4892)clone3(2)'s CLONE_INTO_CGROUP flag when
configuring the runc exec process. This also included some internal
changes to how we add processes to containers. (#4822, #4812, #4920)set_mempolicy(2). (opencontainers/runtime-spec#1282, #4726, #4915)intelRdt.schemata to allow for configuration of all
schemas in resctrl. (opencontainers/runtime-spec#1230, #4830, #4915)intelRdt.enableMonitoring to allow for per-container
resctrl monitoring. This replaces the old intelRdt.enableCMT and
intelRdt.enableMBM options which were never implemented by runc and have
been removed from the runtime-spec. (opencontainers/runtime-spec#1287,
#4832, #4921)personality(2) before applying seccomp profiles. (#4900, #4903)Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →