Environment Variable Injection Flaw in CRI-O by Red Hat
CVE-2026-15809
Key Information:
- Vendor
Red Hat
- Status
- Vendor
- CVE Published:
- 15 July 2026
What is CVE-2026-15809?
A significant vulnerability exists in CRI-O, stemming from an inadequate fix for a previous flaw. This issue permits an attacker who can influence container environment variables to inject newline characters into the HOME variable. Consequently, malicious actors could manipulate the /etc/passwd file by introducing arbitrary entries, posing a severe risk to system integrity and security. This vulnerability highlights the importance of robust validation procedures in container environments.
Affected Version(s)
Red Hat OpenShift Container Platform 4.12 0:1.25.5-36.rhaos4.12.git2e7f657.el8
Red Hat OpenShift Container Platform 4.13 0:1.26.5-32.rhaos4.13.git1088e36.el8
Red Hat OpenShift Container Platform 4.16 0:1.29.13-14.rhaos4.16.git84cfdc6.el8
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved