NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #257 by repository stars
Last release 3 days ago
29 Sep 2026
Ships on a steady schedule
a new release about every 9 days
Most releases are documented
notes for 44 of 55 stable releases
Nothing withdrawn
no release was ever pulled
13 years old
7458 releases · first in 2014
Nothing published for this version
Nothing published for this version
Nothing published for this version
One column per quarter.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
The deprecated libcontainer/user package has been removed; use github.com/moby/sys/user instead. (#3999, #4617)
おめェもボスになったんだろぉ?
This version of runc requires Go 1.24 to build.
libcontainer/user package has been removed; use
github.com/moby/sys/user instead. (#3999, #4617)libcontainer/apparmor variables containing public functions have been
switched to wrapper functions. (#4725)runc update no longer allows --l3-cache-schema or --mem-bw-schema if
linux.intelRdt was not present in the container’s original config.json.
Without linux.intelRdt no CLOS (resctrl group) is created at container
creation, so it is not possible to apply the updated options with runc update.
Previously, this scenario did not work as expected. The runc update would
create a new CLOS but fail to apply the schema, move only the init process
(omitting children) to the new group, and leave the CLOS orphaned after
container exit. (#4827)
The deprecated --criu flag has been removed entirely, instead the criu
binary in $PATH will be used. (#4722)
linux.netDevices field to allow for devices to be
moved into container network namespaces seamlessly. (#4538)runc update now supports per-device weight and iops cgroup limits. (#4775)chown(uid, -1) when configuring the console inode, to avoid issues
with unmapped GIDs. (#4679)runc exec by avoiding calling into SELinux's Set.*Label when
processLabel is not set. (#4354)linux.rootfsPropagation to shared or unbindable now functions
properly. (#1755, #1815, #4724)runc update will no longer clear intelRdt state information. (#4828)runc create and runc delete that would
previously result in spurious errors. (#4735)pidfd_send_signal(2) support when available. (#4666)state.json 25% smaller. (#4685)-EINTR handling
less cumbersome for the rest of runc. (#4697)/proc/net/dev is no longer included in the permitted procfs overmount
list. Its inclusion was almost certainly an error, and because
/proc/net is a symlink to /proc/self/net, overmounting this was
almost certainly never useful (and will be blocked by future kernel
versions). (#4817)toolchain from go.mod and add a CI check to make sure it's
never added accidentally. (#4717, #4721)exclude or replace directives in go.mod, to make sure
that go install doesn't get accidentally broken. (#4750)Among some performance improvements and bugfixes, it includes a fix for a low-severity vulnerability ( CVE-2026-41579 ) and users are encouraged to up…
This is the sixth patch release of the 1.3.z series of runc. Among some
performance improvements and bugfixes, it includes a fix for a
low-severity vulnerability (CVE-2026-41579) and users are encouraged to
update. As it was a low-severity vulnerability and it was reported by
multiple people, we decided to release it publicly with NO EMBARGO.
This release includes a fix for the following low-severity security issue:
CVE-2026-41579 allowed a malicious image with a /dev symlink to have
limited write access to the host filesystem in ways that our analysis
indicates was too limited to be problematic in practice. This bug was very
similar to those fixed in CVE-2025-31133, CVE-2025-52565,
CVE-2025-31133 and was simply missed at the time when we hardened the
rootfs preparation code. We have conducted a deeper audit and not found any
other problematic cases.
This patchset required backports for #5190 and #5285, which were primarily
code reorganisations that were already backported to runc 1.4 and 1.5.
runc exec orrunc run when the container process runs for a short time. (#5208,maskPaths, runc will now re-use a singletmpfs instance (which is not writable) to reduce the number tmpfsThe runc binary distributed with this release are statically linked with
the following GNU LGPL-2.1 licensed libraries, with runc acting
as a "work that uses the Library":
The versions of these libraries were not modified from their upstream versions,
but in order to comply with the LGPL-2.1 (§6(a)), we have attached the
complete source code for those libraries which (when combined with the attached
runc source code) may be used to exercise your rights under the LGPL-2.1.
However we strongly suggest that you make use of your distribution's packages
or download them from the authoritative upstream sources, especially since
these libraries are related to the security of your containers.
Thanks to the following contributors for making this release possible:
Signed-off-by: Aleksa Sarai cyphar@cyphar.com
runc 1.3.6 -- "On no account should you allow a Vogon to read poetry at you."
Compare
This is the fifth patch release of the 1.3.z release series of runc, and primarily contains a few fixes for issues found in 1.3.4.
This is the fifth patch release of the 1.3.z release series of runc,
and primarily contains a few fixes for issues found in 1.3.4.
cannot start a container that has stopped errors whenrunc create and has thus been reverted. (#5158,The runc binary distributed with this release are statically linked with
the following GNU LGPL-2.1 licensed libraries, with runc acting
as a "work that uses the Library":
The versions of these libraries were not modified from their upstream versions,
but in order to comply with the LGPL-2.1 (§6(a)), we have attached the
complete source code for those libraries which (when combined with the attached
runc source code) may be used to exercise your rights under the LGPL-2.1.
However we strongly suggest that you make use of your distribution's packages
or download them from the authoritative upstream sources, especially since
these libraries are related to the security of your containers.
Thanks to the following contributors for making this release possible:
This fixes a regression introduced in our [CVE-2025-52881][] mitigation patches. (#4971, #4973, #4976)
Take me to your heart, take me to your soul.
tmpfs mount, only set the mode= argument if the
target path already existed. This fixes a regression introduced in our
CVE-2025-52881 mitigation patches. (#4971, #4973, #4976)github.com/cyphar/filepath-securejoin dependency to v0.5.2,
which should make it easier for some downstreams to import runc without
pulling in too many extra packages. (#5028)[CVE-2025-31133][] exploits an issue with how masked paths are implemented in runc. When masking files, runc will bind-mount the container's /dev/null…
奴らに支配されていた恐怖を
This release includes fixes for the following high-severity security issues:
CVE-2025-31133 exploits an issue with how masked paths are implemented in
runc. When masking files, runc will bind-mount the container's /dev/null
inode on top of the file. However, if an attacker can replace /dev/null
with a symlink to some other procfs file, runc will instead bind-mount the
symlink target read-write. This issue affected all known runc versions.
CVE-2025-52565 is very similar in concept and application to
CVE-2025-31133, except that it exploits a flaw in /dev/console
bind-mounts. When creating the /dev/console bind-mount (to /dev/pts/$n),
if an attacker replaces /dev/pts/$n with a symlink then runc will
bind-mount the symlink target over /dev/console. This issue affected all
versions of runc >= 1.0.0-rc3.
CVE-2025-52881 is a more sophisticated variant of CVE-2019-19921, which was a flaw that allowed an attacker to trick runc into writing the LSM process labels for a container process into a dummy tmpfs file and thus not apply the correct LSM labels to the container process. The mitigation we applied for CVE-2019-19921 was fairly limited and effectively only caused runc to verify that when we write LSM labels that those labels are actual procfs files. This issue affects all known runc versions.
runc update now supports configuring per-device weights and iops. (#4775,
#4807, #4825, #4931)> Ночь, улица, фонарь, аптека...
Ночь, улица, фонарь, аптека...
Improvements to the deprecation warnings as part of the github.com/opencontainers/cgroups split. (#4784, #4788)
この瓦礫の山でよぉ
linux.rootfsPropagation to shared or unbindable now functions
properly. (#1755, #1815, #4724, #4789)runc delete and runc stop can now correctly handle cases where runc create was killed during setup. Previously it was possible for the
container to be in such a state that neither runc stop nor runc delete
would be unable to kill or delete the container. (#4534, #4645, #4757,
#4793)runc update will no longer clear intelRdt state information. (#4828,
#4833)github.com/opencontainers/cgroups split. (#4784, #4788)/proc/net/dev is no longer included in the permitted procfs overmount
list. Its inclusion was almost certainly an error, and because /proc/net
is a symlink to /proc/self/net, overmounting this was almost certainly
never useful (and will be blocked by future kernel versions). (#4817, #4820)prepareCriuRestoreMounts logic for checkpoint-restore.
(#4765, #4871)golangci-lint to v2.1. (#4747, #4754)> Mr. President, we must not allow a mine shaft gap!
Mr. President, we must not allow a mine shaft gap!
runc pause or runc unpause as an unprivileged user without
--systemd-cgroups. Now the warning is only emitted if an actual permission
error was encountered. (#4709)runc version information is now filled in using //go:embed rather than
being set through Makefile. This allows go install or other non-make
builds to contain the correct version information. Note that make EXTRA_VERSION=... still works. (#418)exclude directives from our go.mod for broken cilium/ebpf
versions. v0.17.3 resolved the issue we had, and exclude directives are
incompatible with go install. (#4748)Use the container's /etc/passwd to set the HOME env var. After a refactor for 1.3, we were setting it reading the host's /etc/passwd file instead. (#4
Eppur si muove.
/etc/passwd to set the HOME env var. After a refactor
for 1.3, we were setting it reading the host's /etc/passwd file instead.
(#4693, #4688)HOME env var if it's set to the empty string. This fixes a
regression after the same refactor for 1.3 and aligns the behavior with older
versions of runc. (#4711)Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →