Topics
+1 more
Affected surfaces
ReleasePort's take
Moderate signalThe release bumps containerd to v2.3.1 to fix a privilege escalation CVE.
Why it matters: Patch containerd to versionβ―v2.3.1 immediately to mitigate the reported privilegeβescalation vulnerability (CVE).
Summary
AI summaryUpdates π¦ Bundled Resource Types, π Bug Fixes, and π οΈ Misc. Changes across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Medium |
Bump containerd to v2.3.1 to address a privilege escalation CVE. Bump containerd to v2.3.1 to address a privilege escalation CVE. Source: llm_adapter@2026-05-24 Confidence: low |
β |
| Bugfix | Medium |
Fix CF connector issues reported by @IvanChalukov. Fix CF connector issues reported by @IvanChalukov. Source: llm_adapter@2026-05-24 Confidence: high |
β |
| Bugfix | Medium |
Use session signing key to derive state signing key. Use session signing key to derive state signing key. Source: llm_adapter@2026-05-24 Confidence: high |
β |
Full changelog
What's Changed
π Bug Fixes
- Fix CF connector by @IvanChalukov in https://github.com/concourse/concourse/pull/9580
- Use session signing key to derive state signing key by @taylorsilva in https://github.com/concourse/concourse/pull/9579
π οΈ Misc. Changes
- Bump containerd to v2.3.1 to address a privilege escalation CVE in containerd by @taylorsilva in https://github.com/concourse/concourse/pull/9582
π¦ Bundled Resource Types
- bosh-io-release: v1.3.4
- bosh-io-stemcell: v1.5.4
- docker-image: v1.13.1
- git: v1.22.3
- github-release: v1.14.0
- hg: v1.5.4
- mock: v0.14.5
- pool: v1.8.1
- registry-image: v1.17.0
- s3: v2.5.4
- semver: v2.0.1
- time: v1.11.3
Full Changelog: https://github.com/concourse/concourse/compare/v8.2.1...v8.2.2
Security Fixes
- containerd upgraded to v2.3.1 β addresses privilege escalation CVE (unspecified ID)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Concourse
Concourse is a container-based automation system written in Go. It's mostly used for CI/CD.
Related context
Related tools
Beta — feedback welcome: [email protected]