Fedora Account System
Red Hat Associate
Red Hat Customer
nitial intake from PSIRTSUPT-23768. Ayato confirmed that CRI-O checkpoint restore can bypass the destination Kubernetes security context when restoring a malicious checkpointed container. Proposed impact is Critical with CVSS 9.9: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. Affected upstream supported versions are >= 1.34, with Red Hat downstream impact from OCP 4.17 onward. Fixes are present in commits f4d95dfe70c4af4afff0c5a96e1a36975c2f65f9, 045d4107f10f9baa4e93d54a93762e0036942d4b, and bb54fa0fba793889d815e5943abd6f8afc938c39. Reporter: lyhtheori. CVE-2026-92574 reserved. Planned disclosure: 2026-09-21. Keep embargoed pending IC review and release confirmation.