{"id":"CVE-2026-92574","summary":"Cri-o: cri-o checkpoint restore bypasses destination security context","details":"A vulnerability in CRI-O checkpoint restore allows a user who can create a pod from a malicious checkpointed container to bypass the destination Kubernetes security context. The restored process may retain credentials, Linux capabilities, no_new_privs, and seccomp state from the checkpoint instead of enforcing the destination configuration. This can allow execution with elevated privileges across the container security boundary.\nAffected upstream supported versions are CRI-O 1.34 and later. Downstream Red Hat products are affected from OCP 4.17 onward. Fixes have been applied to supported branches but are not yet released.\nExploitation requires permission to create a pod from a malicious checkpoint image and checkpoint restore functionality to be available.","modified":"2026-10-03T03:30:17.636495151Z","published":"2026-09-21T09:49:49.679Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92574.json","cna_assigner":"redhat","cwe_ids":["CWE-250"]},"references":[{"type":"WEB","url":"https://access.redhat.com/downloads/content/package-browser/"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2026-92574"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92574.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92574"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2535436"},{"type":"PACKAGE","url":"https://github.com/cri-o/cri-o"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/cri-o/cri-o","events":[{"introduced":"d91a449706dbbd6c285e4d365bbd3b65fd8de43c"},{"fixed":"dcc865df61cc1b8883461ba36ee1e87849bf1d55"},{"introduced":"92c18a2e2673764cd10f89b1a5061e2b26f44209"},{"fixed":"c79f8aef829ec309415c1896a8ceb1be85e17d1e"},{"introduced":"d1e7bdc854ed4846a7f15c5e0c17e0140a1d817b"},{"fixed":"9209fd24af47bd91ffa36f0d47edb7729783be00"}],"database_specific":{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"1.34.0"},{"fixed":"1.34.14"},{"introduced":"1.35.0"},{"fixed":"1.35.9"},{"introduced":"1.36.0"},{"fixed":"1.36.6"}]}}],"versions":["v1.35.8","v1.34.13","v1.36.5","v1.35.7","v1.34.12","v1.36.4","v1.34.11","v1.36.3","v1.35.6","v1.35.5","v1.34.10","v1.36.2","v1.34.9","v1.35.4","v1.36.1","v1.35.3","v1.36.0","v1.34.8","v1.34.7","v1.35.2","v1.34.6","v1.35.1","v1.34.5","v1.35.0","v1.34.4","v1.34.3","v1.34.2","v1.34.1","v1.34.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92574.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}