Bug 2543871

Summary: CVE-2026-62146 cri-o1.32: cri-o: Sandbox state poisoning via pod annotations may expose runtime socket [fedora-43]
Product: [Fedora] Fedora Reporter: Yadnyawalk Tale <ytale>
Component: cri-o1.32Assignee: Brad Smith <bradley.g.smith>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: 43CC: bradley.g.smith, go-sig
Target Milestone: ---Keywords: Security, SecurityTracking
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard: {"flaws": ["eb80abbe-8bce-4dc7-8f12-16860ebcd777"]}
Fixed In Version: Doc Type: ---
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 2499618    

Description Yadnyawalk Tale 2026-09-30 10:36:38 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

A flaw was found in CRI-O. CRI-O persists reserved internal sandbox metadata alongside untrusted pod-supplied annotations without adequate separation, allowing a crafted pod annotation to overwrite that reserved state before it is saved to disk; after a CRI-O restart or node reboot, this poisoned value is reloaded as trusted and used by a later container recreate in the same sandbox, which can result in a host-side runtime-management resource being bind-mounted into the container. A container that gains access to this resource may be able to direct the runtime to act with host privileges, resulting in container escape and full node compromise. This does not require a privileged pod, hostPath, or a custom RuntimeClass, only the ability to create a pod plus a subsequent runtime restart/recreate.