{"id":"AZL-105348","summary":"CVE-2026-62146 affecting package cri-o 1.30.1-1","details":"A trust-boundary flaw in CRI-O's sandbox state persistence allows attacker-influenced pod metadata to overwrite CRI-O's own reserved sandbox bookkeeping; once reloaded as trusted after a restart, a later container recreate in that sandbox can expose a host-side runtime-management resource inside the container, enabling container escape.","modified":"2026-10-05T05:32:41Z","published":"2026-09-30T12:17:13Z","upstream":["CVE-2026-62146"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-62146"}],"affected":[{"package":{"name":"cri-o","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/cri-o"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"1.30.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-105348.json"}}],"schema_version":"1.9.0"}