Sceawere
Vulnerability Detail
CVE-2026-62146UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
CRI-O Sandbox State Injection
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.8
- Creation Date
- 4h ago
- Vendor
- Red Hat
- Product
- Red Hat OpenShift Container Platform 4
- Attack Type
- Trust Boundary Violation
- Vector String
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
A trust-boundary flaw in CRI-O's sandbox state persistence allows attacker-influenced pod metadata to overwrite CRI-O's own reserved sandbox bookkeeping; once reloaded as trusted after a restart, a later container recreate in that sandbox can expose a host-side runtime-management resource inside the container, enabling container escape.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.8",
"pubDate": "2026-09-30T12:17:13.617Z",
"pubdate": "2026-09-30T12:17:13.617Z",
"executiveSummary": "This vulnerability involves a critical trust-boundary flaw within the CRI-O container runtime, specifically concerning the handling of sandbox state persistence.\nThe issue permits an attacker to influence pod metadata, which is subsequently written to disk as part of the sandbox's persisted state.\nUpon a CRI-O service restart, the runtime treats this attacker-controlled metadata as trusted, allowing for the corruption of reserved sandbox bookkeeping.\nThe primary impact is a container breakout, where an attacker can force the container to mount or expose sensitive host-side runtime-management resources.\nSuccessful exploitation requires the ability to influence pod configuration, typically through access to the Kubernetes API or similar orchestration interfaces.\nThe vulnerability represents a significant breach of isolation guarantees, potentially granting the attacker arbitrary host-level code execution and full cluster node compromise.",
"technicalDetails": "The vulnerability stems from inadequate sanitization and trust-boundary enforcement during the persistence and reloading lifecycle of CRI-O sandbox states.\nCRI-O manages sandbox metadata in a persistent store to ensure operational continuity across daemon restarts. The flaw exists because the metadata structure utilized for sandbox bookkeeping does not strictly distinguish between system-reserved configuration and user-provided (or attacker-influenced) pod metadata.\nThe attack flow initiates when an attacker with sufficient permissions to create or update pod configurations injects malicious data into the pod metadata fields that CRI-O processes during sandbox creation. Because the runtime fails to validate the integrity of this state upon serialization, the malicious payload is committed to the persisted sandbox configuration file on the host filesystem.\nWhen the CRI-O daemon restarts, it re-reads these configuration files to reconstruct its internal state. It treats the previously persisted malicious metadata as a trusted source of truth, effectively importing the attacker-influenced parameters into its privileged memory space.\nDuring the lifecycle of the container—specifically when a pod is recreated or a container is restarted within that sandbox—CRI-O utilizes the corrupted bookkeeping data to configure runtime resources. By manipulating internal state variables via the persisted metadata, an attacker can coerce the runtime into mounting host-path resources or runtime-management sockets (such as cgroup controllers, host namespaces, or Docker/CRI-O control sockets) directly into the target container.\nThis modification subverts the container isolation primitives. Once the host-side resource is exposed within the container, the attacker can leverage standard container escape techniques to interact with the host kernel or the container runtime API, leading to full compromise of the underlying node. The vulnerability effectively turns a metadata injection primitive into a host-level privilege escalation vector."
}