UBUNTU-CVE-2026-18107

Source
https://ubuntu.com/security/CVE-2026-18107
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-18107.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2026-18107
Upstream
  • CVE-2026-18107
Published
2026-07-28T19:17:00Z
Modified
2026-08-06T03:08:40Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

A flaw was found in CRIU's handling of restartable sequences (rseq) during checkpoint/restore. A malicious process inside a container can register an rseq critical section that hijacks CRIU's parasite code injection during checkpoint, allowing it to spoof the process credentials saved in the checkpoint image. On restore, the container process gains elevated capabilities and zeroed UIDs/GIDs. The practical impact on Red Hat products is limited by several factors: checkpoint/restore requires root privileges (podman) or cluster-admin RBAC (OpenShift) to trigger and cannot be initiated from within the container itself; on OpenShift prior to 4.17 the feature required explicit opt-in, and on 4.17+ the kubelet checkpoint API RBAC is not configured by default; OpenShift enforces user namespaces by default for regular workloads (hostUsers is gated behind admin-only SCCs), which makes the spoofed capabilities namespace-scoped and ineffective for privilege escalation; SELinux type enforcement (container_t) blocks privilege transitions independently of capabilities; seccomp filters persist through checkpoint/restore and cannot be corrupted via the parasite; and kernel mount namespace ownership checks on RHEL 9/10 kernels prevent mount-based container escape even with spoofed capabilities.

References

Affected packages

Ubuntu:16.04:LTS / criu

Package

Name
criu
Purl
pkg:deb/ubuntu/criu?arch=source&distro=xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.7-2
1.7-3
1.7.2-1
1.7.2-2
1.8-2
2.*
2.0-2ubuntu1
2.0-2ubuntu2
2.0-2ubuntu3
2.6-1ubuntu1~ubuntu16.04.2

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "criu",
            "binary_version": "2.6-1ubuntu1~ubuntu16.04.2"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-18107.json"

Ubuntu:18.04:LTS / criu

Package

Name
criu
Purl
pkg:deb/ubuntu/criu?arch=source&distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.4-3
3.5-2
3.6-2

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "criu",
            "binary_version": "3.6-2"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-18107.json"

Ubuntu:22.04:LTS / criu

Package

Name
criu
Purl
pkg:deb/ubuntu/criu?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.14-1
3.16.1-2

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "criu",
            "binary_version": "3.16.1-2"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-18107.json"

Ubuntu:26.04:LTS / criu

Package

Name
criu
Purl
pkg:deb/ubuntu/criu?arch=source&distro=resolute

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

4.*
4.1.1-1build1
4.2-1ubuntu1
4.2-1ubuntu2

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "criu",
            "binary_version": "4.2-1ubuntu2"
        },
        {
            "binary_name": "libcompel1",
            "binary_version": "4.2-1ubuntu2"
        },
        {
            "binary_name": "libcriu2",
            "binary_version": "4.2-1ubuntu2"
        },
        {
            "binary_name": "python3-pycriu",
            "binary_version": "4.2-1ubuntu2"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-18107.json"