CRI-O 中的检查点恢复(checkpoint restore)功能存在一个安全漏洞,允许能够使用恶意检查点容器创建 Pod 的用户绕过目标 Kubernetes 集群的安全上下文策略。恢复后的进程可能保留来自检查点的凭据、Linux 能力(capabilities)、no_new_privs 标志以及 seccomp 状态,而不会强制应用目标环境的配置。这可能导致在容器安全边界之外执行提升权限的操作。 受影响的上游支持版本为 CRI-O 1.34 及更高版本。下游 Red Hat 产品中,从 OpenShift
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Confidential Compute Attestation | any |
unaffected |
| Red Hat | Red Hat Enterprise Linux 8 | any |
unaffected |
any |
unaffected | ||
| Red Hat | Red Hat Enterprise Linux 9 | any |
unaffected |
| Red Hat | Red Hat OpenShift Container Platform 4 | any |
unaffected |
any |
affected | ||
any |
unaffected | ||
any |
unaffected | ||
any |
unaffected | ||
any |
unaffected | ||
any |
unaffected | ||
any |
unaffected | ||
| … +2 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-15801 | 8.0 HIGH | Cri-o: cri-o: insufficient validation during container checkpoint restore |
| CVE-2026-94215 | 5.5 MEDIUM | Keycloak-services: keycloak-services: cross-realm client read/write via request-level cach |
| CVE-2026-94213 | 4.9 MEDIUM | Keycloak-services: keycloak-services: authorization services policy evaluation endpoint le |
| CVE-2026-94217 | 3.5 LOW | Keycloak-services: keycloak-services: uma scope merge across resource owners via resource |
| CVE-2026-94218 | 3.1 LOW | Keycloak-services: keycloak-services: 2fa setup enforcement bypass via authentication sess |
No comments yet