Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-92574— Cri-o: cri-o checkpoint restore bypasses destination security context

Quick assessment

Affected
Red Hat Confidential Compute Attestation
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

CRI-O 中的检查点恢复(checkpoint restore)功能存在一个安全漏洞,允许能够使用恶意检查点容器创建 Pod 的用户绕过目标 Kubernetes 集群的安全上下文策略。恢复后的进程可能保留来自检查点的凭据、Linux 能力(capabilities)、no_new_privs 标志以及 seccomp 状态,而不会强制应用目标环境的配置。这可能导致在容器安全边界之外执行提升权限的操作。 受影响的上游支持版本为 CRI-O 1.34 及更高版本。下游 Red Hat 产品中,从 OpenShift

CVSS 8.8 · High

Affected Version Matrix 14

VendorProduct Version RangeStatus
Red Hat Confidential Compute Attestation any unaffected
Red Hat Red Hat Enterprise Linux 8 any unaffected
any unaffected
Red Hat Red Hat Enterprise Linux 9 any unaffected
Red Hat Red Hat OpenShift Container Platform 4 any unaffected
any affected
any unaffected
any unaffected
any unaffected
any unaffected
any unaffected
any unaffected
… +2 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-92574

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Cri-o: cri-o checkpoint restore bypasses destination security context
Source: CVE Program / CVE List V5
Vulnerability Description
A vulnerability in CRI-O checkpoint restore allows a user who can create a pod from a malicious checkpointed container to bypass the destination Kubernetes security context. The restored process may retain credentials, Linux capabilities, no_new_privs, and seccomp state from the checkpoint instead of enforcing the destination configuration. This can allow execution with elevated privileges across the container security boundary. Affected upstream supported versions are CRI-O 1.34 and later. Downstream Red Hat products are affected from OCP 4.17 onward. Fixes have been applied to supported branches but are not yet released. Exploitation requires permission to create a pod from a malicious checkpoint image and checkpoint restore functionality to be available.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
带着不必要的权限执行
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Confidential Compute Attestation - cpe:/a:redhat:confidential_compute_attestation:1
Red Hat Red Hat Enterprise Linux 8 - cpe:/o:redhat:enterprise_linux:8
Red Hat Red Hat Enterprise Linux 8 - cpe:/o:redhat:enterprise_linux:8
Red Hat Red Hat Enterprise Linux 9 - cpe:/o:redhat:enterprise_linux:9
Red Hat Red Hat OpenShift Container Platform 4 - cpe:/a:redhat:openshift:4
Red Hat Red Hat OpenShift Container Platform 4 - cpe:/a:redhat:openshift:4
Red Hat Red Hat OpenShift Container Platform 4 - cpe:/a:redhat:openshift:4
Red Hat Red Hat OpenShift Container Platform 4 - cpe:/a:redhat:openshift:4
Red Hat Red Hat OpenShift Container Platform 4 - cpe:/a:redhat:openshift:4
Red Hat Red Hat OpenShift Container Platform 4 - cpe:/a:redhat:openshift:4
Red Hat Red Hat OpenShift Container Platform 4 - cpe:/a:redhat:openshift:4
Red Hat Red Hat OpenShift Container Platform 4 - cpe:/a:redhat:openshift:4
Red Hat Red Hat OpenShift Container Platform 4 - cpe:/a:redhat:openshift:4
Red Hat Red Hat OpenShift Container Platform 4 - cpe:/a:redhat:openshift:4

II. Public POCs for CVE-2026-92574

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-92574

登录查看更多情报信息。

Vendor Advisories for CVE-2026-92574 (2)

Same Patch Batch · Red Hat · 2026-09-21 · 6 CVEs total

CVE-2026-15801 8.0 HIGH Cri-o: cri-o: insufficient validation during container checkpoint restore
CVE-2026-94215 5.5 MEDIUM Keycloak-services: keycloak-services: cross-realm client read/write via request-level cach
CVE-2026-94213 4.9 MEDIUM Keycloak-services: keycloak-services: authorization services policy evaluation endpoint le
CVE-2026-94217 3.5 LOW Keycloak-services: keycloak-services: uma scope merge across resource owners via resource
CVE-2026-94218 3.1 LOW Keycloak-services: keycloak-services: 2fa setup enforcement bypass via authentication sess

IV. Related Vulnerabilities

V. Comments for CVE-2026-92574

No comments yet


Leave a comment