Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-18107— Criu: criu: container escape via rseq critical section hijack during checkpoint/restore

Quick assessment

Affected
Red Hat Red Hat Enterprise Linux 10
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

checkpoint-restore CRIU是checkpoint-restore组织的一个Linux进程检查点与恢复工具。 checkpoint-restore CRIU存在权限许可和访问控制问题漏洞,该漏洞源于CRIU对重启序列(rseq)处理不当,可能导致容器内恶意进程通过劫持检查点注入伪造凭证,从而在恢复时获得高权限和清零的UID/GID。

CVSS 7.8 · High EPSS 0.11% · P1

Affected Version Matrix 8

VendorProduct Version RangeStatus
Red Hat Red Hat Enterprise Linux 10 any affected
Red Hat Red Hat Enterprise Linux 7 any affected
Red Hat Red Hat Enterprise Linux 8 any affected
any affected
Red Hat Red Hat Enterprise Linux 9 any affected
Red Hat Red Hat OpenShift Container Platform 4 any affected
any affected
any affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-18107

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Criu: criu: container escape via rseq critical section hijack during checkpoint/restore
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in CRIU's handling of restartable sequences (rseq) during checkpoint/restore. A malicious process inside a container can register an rseq critical section that hijacks CRIU's parasite code injection during checkpoint, allowing it to spoof the process credentials saved in the checkpoint image. On restore, the container process gains elevated capabilities and zeroed UIDs/GIDs. The practical impact on Red Hat products is limited by several factors: checkpoint/restore requires root privileges (podman) or cluster-admin RBAC (OpenShift) to trigger and cannot be initiated from within the container itself; on OpenShift prior to 4.17 the feature required explicit opt-in, and on 4.17+ the kubelet checkpoint API RBAC is not configured by default; OpenShift enforces user namespaces by default for regular workloads (hostUsers is gated behind admin-only SCCs), which makes the spoofed capabilities namespace-scoped and ineffective for privilege escalation; SELinux type enforcement (container_t) blocks privilege transitions independently of capabilities; seccomp filters persist through checkpoint/restore and cannot be corrupted via the parasite; and kernel mount namespace ownership checks on RHEL 9/10 kernels prevent mount-based container escape even with spoofed capabilities.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
特权管理不恰当
Source: CVE Program / CVE List V5
Vulnerability Title
checkpoint-restore CRIU 权限许可和访问控制问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
checkpoint-restore CRIU是checkpoint-restore组织的一个Linux进程检查点与恢复工具。 checkpoint-restore CRIU存在权限许可和访问控制问题漏洞,该漏洞源于CRIU对重启序列(rseq)处理不当,可能导致容器内恶意进程通过劫持检查点注入伪造凭证,从而在恢复时获得高权限和清零的UID/GID。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat Enterprise Linux 10 - cpe:/o:redhat:enterprise_linux:10
Red Hat Red Hat Enterprise Linux 7 - cpe:/o:redhat:enterprise_linux:7
Red Hat Red Hat Enterprise Linux 8 - cpe:/o:redhat:enterprise_linux:8
Red Hat Red Hat Enterprise Linux 8 - cpe:/o:redhat:enterprise_linux:8
Red Hat Red Hat Enterprise Linux 9 - cpe:/o:redhat:enterprise_linux:9
Red Hat Red Hat OpenShift Container Platform 4 - cpe:/a:redhat:openshift:4
Red Hat Red Hat OpenShift Container Platform 4 - cpe:/a:redhat:openshift:4
Red Hat Red Hat OpenShift Container Platform 4 - cpe:/a:redhat:openshift:4

II. Public POCs for CVE-2026-18107

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-18107

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-18107 (1)

Vendor Advisories for CVE-2026-18107 (2)

Same Patch Batch · Red Hat · 2026-07-28 · 5 CVEs total

CVE-2026-49332 8.5 HIGH Openshift/oauth-proxy: openshift/oauth-proxy: underscore header smuggling enables identity
CVE-2026-16313 7.6 HIGH Sg3_utils: sg3_utils: arbitrary command execution via udev property injection in sg_inq --
CVE-2026-18047 6.5 MEDIUM Dogtag-pki: pki-core: redhat-pki: pki: acme admin enable/disable endpoint authentication b
CVE-2026-17072 3.3 LOW Gstreamer1-plugins-good: gst-plugins-good: 4-byte heap over-read in gst_matroska_parse_fla

IV. Related Vulnerabilities

V. Comments for CVE-2026-18107

No comments yet


Leave a comment