Bug 2499618 (CVE-2026-62146) - CVE-2026-62146 cri-o: cri-o: Sandbox state poisoning via pod annotations may expose runtime socket
Summary: CVE-2026-62146 cri-o: cri-o: Sandbox state poisoning via pod annotations may ...
Keywords:
Status: NEW
Alias: CVE-2026-62146
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2543868 2543870 2543871 2543872 2543873 2543874 2543875 2543876 2543890 2543891 2543892 2543894
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-13 09:48 UTC by OSIDB Bzimport
Modified: 2026-09-30 11:58 UTC (History)
17 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-07-13 09:48:00 UTC
A flaw was found in CRI-O. CRI-O persists reserved internal sandbox metadata alongside untrusted pod-supplied annotations without adequate separation, allowing a crafted pod annotation to overwrite that reserved state before it is saved to disk; after a CRI-O restart or node reboot, this poisoned value is reloaded as trusted and used by a later container recreate in the same sandbox, which can result in a host-side runtime-management resource being bind-mounted into the container. A container that gains access to this resource may be able to direct the runtime to act with host privileges, resulting in container escape and full node compromise. This does not require a privileged pod, hostPath, or a custom RuntimeClass, only the ability to create a pod plus a subsequent runtime restart/recreate.

Comment 1 Yadnyawalk Tale 2026-07-13 09:56:52 UTC
CVSS Justification:

AV:L (Local) — The vulnerable component (CRI-O daemon/socket) isn't network-reachable; exploitation requires a workload already scheduled on the affected node.
AC:H (High) — Requires a specific timing condition beyond attacker control: a CRI-O restart/node reboot followed by a container recreate in the same sandbox.
PR:L (Low) — Attacker only needs the ability to create a Pod with a crafted annotation, not elevated/admin cluster privileges.
UI:N (None) — No action from another user or admin is needed once the pod is created and the restart/recreate condition occurs.
S:C (Changed) — The flaw crosses from the container's security scope into the host's, since it exposes a host-level control socket inside the container.
C:H (High) — Access to the exposed runtime socket lets an attacker read host/runtime state and other containers' data.
I:H (High) — The same socket access allows issuing commands to the container runtime, letting an attacker modify host-managed resources.
A:H (High) — Runtime-level control via the socket can be used to disrupt or take down containers/workloads on the node.


Note You need to log in before you can comment on or make changes to this bug.