Bug 2535436 (CVE-2026-92574) - CVE-2026-92574 cri-o: CRI-O checkpoint restore bypasses destination security context
Summary: CVE-2026-92574 cri-o: CRI-O checkpoint restore bypasses destination security ...
Keywords:
Status: NEW
Alias: CVE-2026-92574
Deadline: 2026-09-21
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-16 13:59 UTC by OSIDB Bzimport
Modified: 2026-09-21 09:21 UTC (History)
20 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-16 13:59:19 UTC
nitial intake from PSIRTSUPT-23768. Ayato confirmed that CRI-O checkpoint restore can bypass the destination Kubernetes security context when restoring a malicious checkpointed container. Proposed impact is Critical with CVSS 9.9: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. Affected upstream supported versions are >= 1.34, with Red Hat downstream impact from OCP 4.17 onward. Fixes are present in commits f4d95dfe70c4af4afff0c5a96e1a36975c2f65f9, 045d4107f10f9baa4e93d54a93762e0036942d4b, and bb54fa0fba793889d815e5943abd6f8afc938c39. Reporter: lyhtheori. CVE-2026-92574 reserved. Planned disclosure: 2026-09-21. Keep embargoed pending IC review and release confirmation.


Note You need to log in before you can comment on or make changes to this bug.