Container Security Bypass in CRI-O by Red Hat
CVE-2026-92574
8.8HIGH
What is CVE-2026-92574?
A vulnerability in CRI-O’s checkpoint restore mechanism allows the execution of pods from a compromised checkpointed container, potentially bypassing Kubernetes security contexts. This issue enables restored processes to retain critical credentials and capabilities from the original checkpoint, which could result in executing with elevated privileges across container boundaries. To exploit this vulnerability, an attacker must have the ability to create a pod using a malicious checkpoint image, necessitating that the checkpoint restore functionality is enabled.
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank lyhtheori for reporting this issue.