Hi Reinhard,

On Wed, Sep 16, 2026 at 11:47:02AM +0000, Debian Bug Tracking System wrote:
> containerd in unstable/testing is not affected by CVE-2026-46680.
> 
> Upstream backported the fix for GHSA-fqw6-gf59-qr4w [1] (commit 2054cc54c,
> PR #13497 [2]) to release/2.1, which was released in v2.1.8 and v2.1.9. Debian
> packaged v2.1.9 as 2.1.9+ds1-1, so unstable is fine.
> 
> Closing with version 2.1.9+ds1-1 to update BTS version tracking for sid/forky.
> The bug remains tracked for trixie/bookworm via the 1.7.24~ds1-1 found marker.

Uh that is odd, because when I checked I think to had considered the
statement:

> Note: The containerd 2.1 release has reached its end of life and a
> fixed version is not provided.

But looking at the fixes for the oldes version the only canidate
sensible looks to be
https://github.com/containerd/containerd/commit/6a05ddd119ec81beb36d504ce844bdd11bfcb22c
(v1.7.32), and then this would indeed match
https://github.com/containerd/containerd/commit/2054cc54c101831e44c83b4185e1e3d09ff50840
which *was* tagged.

So is the upstream information in the GHSA wrong, and do we have the
right mapping?

Regards,
Salvatore

Reply via email to