NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #257 by repository stars
Last release today
02 Oct 2026
Ships on a steady schedule
a new release about every 9 days
Most releases are documented
notes for 44 of 55 stable releases
Nothing withdrawn
no release was ever pulled
13 years old
7461 releases · first in 2014
Nothing published for this version
Nothing published for this version
Nothing published for this version
One column per quarter.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
> No tengo miedo al invierno, con tu recuerdo lleno de sol.
No tengo miedo al invierno, con tu recuerdo lleno de sol.
configs.CommandHook struct has changed, Command is now a pointer.
Also, configs.NewCommandHook now accepts a *Command. (#4325)Process struct has User string field replaced with numeric
UID and GID fields, and AdditionalGroups changed its type from
[]string to []int. Essentially, resolution of user and group
names to IDs is no longer performed by libcontainer, so if a libcontainer
user previously relied on this feature, now they have to convert names to
IDs before calling libcontainer; it is recommended to use Go package
github.com/moby/sys/user for that. (#3999)runc exec -p no longer ignores specified ioPriority and scheduler
settings. Similarly, libcontainer's Container.Start and Container.Run
methods no longer ignore Process.IOPriority and Process.Scheduler
settings. (#4585)F_SEAL_FUTURE_WRITE when sealing the runc binary, as it
turns out this had some unfortunate bugs in older kernel versions and was
never necessary in the first place. (#4641, #4640)nsenter(8). This is mainly useful for users that
create a container with a runc-managed user namespace but want the container
to join some externally-managed namespace as well. (#4492)runc now properly handles joining time namespaces (such as with runc exec). Previously we would attempt to set the time offsets when joining,
which would fail. (#4635, #4636)EINTR retries correctly for socket-related direct
golang.org/x/sys/unix system calls. (#4637)close_range(2) errors more gracefully. (#4596)O_CLOEXEC with
CloseExecFrom failed (#4599).RELEASES.md for more details. (#4557)strings.Cut where appropriate.
(#4470)runc exec. (#4327)runc_nocriu. (#4546)pidfd-socket.
(#4045)skip-in-flight and link-remap options for CRIU. (#4627)noprefix. (#4513)Nothing published for this version
This fixes a regression introduced in our [CVE-2025-52881][] mitigation patches. (#4971, #4974)
Stars hide your fires, let me rest tonight.
tmpfs mount, only set the mode= argument if the
target path already existed. This fixes a regression introduced in our
CVE-2025-52881 mitigation patches. (#4971, #4974)github.com/cyphar/filepath-securejoin dependency to v0.5.2,
which should make it easier for some downstreams to import runc without
pulling in too many extra packages. (#5027)[CVE-2025-31133][] exploits an issue with how masked paths are implemented in runc. When masking files, runc will bind-mount the container's /dev/null…
鳥籠の中に囚われた屈辱を
This release includes fixes for the following high-severity security issues:
CVE-2025-31133 exploits an issue with how masked paths are implemented in
runc. When masking files, runc will bind-mount the container's /dev/null
inode on top of the file. However, if an attacker can replace /dev/null
with a symlink to some other procfs file, runc will instead bind-mount the
symlink target read-write. This issue affected all known runc versions.
CVE-2025-52565 is very similar in concept and application to
CVE-2025-31133, except that it exploits a flaw in /dev/console
bind-mounts. When creating the /dev/console bind-mount (to /dev/pts/$n),
if an attacker replaces /dev/pts/$n with a symlink then runc will
bind-mount the symlink target over /dev/console. This issue affected all
versions of runc >= 1.0.0-rc3.
CVE-2025-52881 is a more sophisticated variant of CVE-2019-19921, which was a flaw that allowed an attacker to trick runc into writing the LSM process labels for a container process into a dummy tmpfs file and thus not apply the correct LSM labels to the container process. The mitigation we applied for CVE-2019-19921 was fairly limited and effectively only caused runc to verify that when we write LSM labels that those labels are actual procfs files. This issue affects all known runc versions.
Nothing published for this version
Removed preemptive "full access to cgroups" warning when calling runc pause or runc unpause as an unprivileged user without --systemd-cgroups. Now the
さんをつけろよデコ助野郎!
runc pause or runc unpause as an unprivileged user without
--systemd-cgroups. Now the warning is only emitted if an actual permission
error was encountered. (#4709, #4720)linux.rootfsPropagation to shared or unbindable now functions
properly. (#1755, #1815, #4724, #4791)runc update will no longer clear intelRdt state information. (#4828,
#4834)/proc/net/dev is no longer included in the permitted procfs overmount
list. Its inclusion was almost certainly an error, and because /proc/net
is a symlink to /proc/self/net, overmounting this was almost certainly
never useful (and will be blocked by future kernel versions). (#4817, #4820)prepareCriuRestoreMounts logic for checkpoint-restore.
(#4765, #4872)Nothing published for this version
We need to drop Ubuntu 20.04 from CI because Github Actions announced it's already deprecated and it will be discontinued soon.
Hasta la victoria, siempre.
O_CLOEXEC with
CloseExecFrom failed (#4647).runc now properly handles joining time namespaces (such as with runc exec). Previously we would attempt to set the time offsets when joining,
which would fail. (#4635, #4649)EINTR retries correctly for socket-related direct
golang.org/x/sys/unix system calls. (#4650)F_SEAL_FUTURE_WRITE when sealing the runc binary, as it
turns out this had some unfortunate bugs in older kernel versions and was
never necessary in the first place. (#4651, #4640)Fexecve helper from libcontainer/system. Runc 1.2.1 removed
runc-dmz, but we forgot to remove this helper added only for that. (#4646)> Мороз и солнце; день чудесный!
Мороз и солнце; день чудесный!
Nothing published for this version
Re-add tun/tap devices to built-in allowed devices lists.
Христос се роди!
Re-add tun/tap devices to built-in allowed devices lists.
In runc 1.2.0 we removed these devices from the default allow-list (which
were added seemingly by accident early in Docker's history) as a precaution
in order to try to reduce the attack surface of device inodes available to
most containers (#3468). At the time we thought that the vast majority of
users using tun/tap would already be specifying what devices they need (such
as by using --device with Docker/Podman) as opposed to doing the mknod
manually, and thus there would've been no user-visible change.
Unfortunately, it seems that this regressed a noticeable number of users (and not all higher-level tools provide easy ways to specify devices to allow) and so this change needed to be reverted. Users that do not need these devices are recommended to explicitly disable them by adding deny rules in their container configuration. (#4555, #4556)
> Winter is not a season, it's a celebration.
Winter is not a season, it's a celebration.
> Specialization is for insects.
Specialization is for insects.
runc delete on a rootless container with no
dedicated cgroup on a system with read-only /sys/fs/cgroup mount.
This is a regression in runc 1.2.0, causing a failure when using
rootless buildkit. (#4518, #4531)> No existe una escuela que enseñe a vivir.
No existe una escuela que enseñe a vivir.
golang.org/x/sys/execabs from go.mod. (#4480)script/check-config.sh script now checks for overlayfs support. (#4494)Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →