CVE-2026-92574

Source
https://cve.org/CVERecord?id=CVE-2026-92574
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92574.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-92574
Published
2026-09-21T09:49:49Z
Modified
2026-10-03T03:30:17Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Cri-o: cri-o checkpoint restore bypasses destination security context
Details

A vulnerability in CRI-O checkpoint restore allows a user who can create a pod from a malicious checkpointed container to bypass the destination Kubernetes security context. The restored process may retain credentials, Linux capabilities, no_new_privs, and seccomp state from the checkpoint instead of enforcing the destination configuration. This can allow execution with elevated privileges across the container security boundary. Affected upstream supported versions are CRI-O 1.34 and later. Downstream Red Hat products are affected from OCP 4.17 onward. Fixes have been applied to supported branches but are not yet released. Exploitation requires permission to create a pod from a malicious checkpoint image and checkpoint restore functionality to be available.

Database specific
{
    "cna_assigner":  "redhat",
    "cwe_ids":  [
        "CWE-250"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92574.json"
}
References

Affected packages

Git / github.com/cri-o/cri-o

Affected ranges

Type
GIT
Repo
https://github.com/cri-o/cri-o
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "1.34.0"
        },
        {
            "fixed":  "1.34.14"
        },
        {
            "introduced":  "1.35.0"
        },
        {
            "fixed":  "1.35.9"
        },
        {
            "introduced":  "1.36.0"
        },
        {
            "fixed":  "1.36.6"
        }
    ],
    "source":  "AFFECTED_FIELD"
}

Affected versions

v1.*
v1.34.0
v1.34.1
v1.34.10
v1.34.11
v1.34.12
v1.34.13
v1.34.2
v1.34.3
v1.34.4
v1.34.5
v1.34.6
v1.34.7
v1.34.8
v1.34.9
v1.35.0
v1.35.1
v1.35.2
v1.35.3
v1.35.4
v1.35.5
v1.35.6
v1.35.7
v1.35.8
v1.36.0
v1.36.1
v1.36.2
v1.36.3
v1.36.4
v1.36.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92574.json"