Bug 2543875 - CVE-2026-62146 cri-o1.36: cri-o: Sandbox state poisoning via pod annotations may expose runtime socket [fedora-44]
Summary: CVE-2026-62146 cri-o1.36: cri-o: Sandbox state poisoning via pod annotations ...
Keywords:
Status: NEW
Alias: None
Product: Fedora
Classification: Fedora
Component: cri-o1.36
Version: 44
Hardware: Unspecified
OS: Unspecified
high
high
Target Milestone: ---
Assignee: Brad Smith
QA Contact:
URL:
Whiteboard: {"flaws": ["eb80abbe-8bce-4dc7-8f12-1...
Depends On:
Blocks: CVE-2026-62146
TreeView+ depends on / blocked
 
Reported: 2026-09-30 10:37 UTC by Yadnyawalk Tale
Modified: 2026-09-30 10:37 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Yadnyawalk Tale 2026-09-30 10:37:28 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

A flaw was found in CRI-O. CRI-O persists reserved internal sandbox metadata alongside untrusted pod-supplied annotations without adequate separation, allowing a crafted pod annotation to overwrite that reserved state before it is saved to disk; after a CRI-O restart or node reboot, this poisoned value is reloaded as trusted and used by a later container recreate in the same sandbox, which can result in a host-side runtime-management resource being bind-mounted into the container. A container that gains access to this resource may be able to direct the runtime to act with host privileges, resulting in container escape and full node compromise. This does not require a privileged pod, hostPath, or a custom RuntimeClass, only the ability to create a pod plus a subsequent runtime restart/recreate.


Note You need to log in before you can comment on or make changes to this bug.