CRI-O Container Runtime Sandbox Persistence Exploit Enables Host Escape
CVE-2026-62146 Published on September 30, 2026

Cri-o: cri-o: sandbox state poisoning via pod annotations may expose runtime socket
A trust-boundary flaw in CRI-O's sandbox state persistence allows attacker-influenced pod metadata to overwrite CRI-O's own reserved sandbox bookkeeping; once reloaded as trusted after a restart, a later container recreate in that sandbox can expose a host-side runtime-management resource inside the container, enabling container escape.

NVD

Vulnerability Analysis

CVE-2026-62146 is exploitable with local system access, and requires small amount of user privileges. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to be very high.

Attack Vector:
LOCAL
Attack Complexity:
HIGH
Privileges Required:
LOW
User Interaction:
NONE
Scope:
CHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH

Timeline

Reported to Red Hat.

Made public. 42 days later.

Weakness Type

Trust Boundary Violation

The product mixes trusted and untrusted data in the same data structure or structured message. A trust boundary can be thought of as line drawn through a program. On one side of the line, data is untrusted. On the other side of the line, data is assumed to be trustworthy. The purpose of validation logic is to allow data to safely cross the trust boundary - to move from untrusted to trusted. A trust boundary violation occurs when a program blurs the line between what is trusted and what is untrusted. By combining trusted and untrusted data in the same data structure, it becomes easier for programmers to mistakenly trust unvalidated data.


Products Associated with CVE-2026-62146

Want to know whenever a new CVE is published for Red Hat Openshift? stack.watch will email you.

 

Affected Versions

Red Hat OpenShift Container Platform 4: