Bug 2496130 (CVE-2026-53492) - CVE-2026-53492 github.com/containerd/containerd: containerd: Security bypass via Container Device Interface (CDI) annotation smuggling during checkpoint restoration.
Summary: CVE-2026-53492 github.com/containerd/containerd: containerd: Security bypass ...
Keywords:
Status: NEW
Alias: CVE-2026-53492
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2496483 2496548 2496549 2496551 2496552 2496553 2496554 2496557 2496558 2496559 2496561 2496562 2496563 2496564 2496565 2496566 2496567 2496568 2496569 2496570 2496571 2496572 2496573 2496550 2496555 2496560
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-01 19:01 UTC by OSIDB Bzimport
Modified: 2026-07-09 15:40 UTC (History)
101 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-07-01 19:01:57 UTC
containerd is an open-source container runtime. In Versions prior to 2.3.2, 2.2.5 and 2.1.9, the CRI implementation improperly trusts Container Device Interface (CDI) annotations found within untrusted checkpoint image metadata during container restoration. When restoring a container from a checkpoint, containerd preserves CDI-related annotations from the checkpoint archive rather than relying solely on the pod's create-time specification. This allows a user with pod creation permissions to bypass standard Kubernetes resource allocation and device plugin enforcement, injecting arbitrary CDI edits (such as device nodes and host mounts) into the restored container. Successful exploitation requires that the node has CDI enabled and contains a matching host CDI specification for the requested device; environments where CDI is disabled or lacking sensitive device specifications are not affected. This issue has been fixed in versions 2.3.2, 2.2.5 and 2.1.9.


Note You need to log in before you can comment on or make changes to this bug.