CRI-O bind_mount_prefix Symlink Spoof leads to Host Path Escalation
CVE-2026-76061 Published on October 6, 2026
Cri-o: cri-o: bind_mount_prefix intermediate-symlink prefix bypass
A flaw was found in CRI-O's `bind_mount_prefix` handling. When configured with a non-empty `bind_mount_prefix`, a malicious container or local attacker could use a Container Runtime Interface (CRI) hostPath containing an intermediate absolute symlink. This could cause the bind mount source to resolve outside the intended prefixed root, potentially leading to unauthorized access to files or privilege escalation on the host system.
Vulnerability Analysis
CVE-2026-76061 can be exploited with network access, and requires user privileges. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to be low. considered to have a small impact on confidentiality and integrity and availability.
Timeline
Reported to Red Hat.
Made public. 39 days later.
Weakness Type
What is an insecure temporary file Vulnerability?
The software attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
CVE-2026-76061 has been classified to as an insecure temporary file vulnerability or weakness.
Products Associated with CVE-2026-76061
Want to know whenever a new CVE is published for Red Hat Openshift? stack.watch will email you.