Description
A trust-boundary flaw in CRI-O's sandbox state persistence allows attacker-influenced pod metadata to overwrite CRI-O's own reserved sandbox bookkeeping; once reloaded as trusted after a restart, a later container recreate in that sandbox can expose a host-side runtime-management resource inside the container, enabling container escape.
Published: 2026-09-30
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: Container Escape
Action: Apply Patch
AI Analysis

Impact

A trust‑boundary flaw in CRI‑O’s sandbox state persistence allows an attacker who can influence pod metadata to overwrite CRI‑O’s own reserved sandbox bookkeeping. Once CRI‑O reloads the altered sandbox after a restart, a container later recreated in the same sandbox may expose the host‑side runtime‑management socket inside the container, effectively leaking a privileged resource and enabling container escape. The weakness is classified as CWE‑501, indicating information exposure through improper handling of resource ownership.

Affected Systems

The vulnerability affects Red Hat OpenShift Container Platform 4. No specific affected sub‑versions are listed, so all current releases of this product are potentially at risk until a vendor fix is released.

Risk and Exploitability

The CVSS score of 7.8 ranks it as high‑severity, reflecting the possibility of host compromise. EPSS is not available, so the exploitation probability remains uncertain, although the lack of KEV listing suggests no widespread exploitation has been reported yet. The likely attack vector requires the attacker to be able to create or update pods with custom annotations, and then trigger a CRI‑O restart or node reboot to reload the tampered sandbox. Once the sandbox is reloaded, the attacker can mount the host‑side runtime socket into a new container, achieving privilege escalation from within the container to the host.

Generated by OpenCVE AI on September 30, 2026 at 13:28 UTC.

Remediation

Vendor Workaround

There is no complete workaround; until a fix is available, administrators should restrict who can create/update pods and set arbitrary annotations via RBAC/admission policy, minimize unnecessary CRI-O restarts or node reboots and monitor for anomalous container mounts (e.g. under /dev/shm) following runtime restarts, then apply the vendor patch once released.


OpenCVE Recommended Actions

  • Apply the Red Hat patch for CVE‑2026‑62146 as soon as it becomes available.
  • Restrict pod creation and annotation modification through RBAC or admission policies, ensuring only trusted users can add arbitrary annotations.
  • Limit unnecessary CRI‑O restarts or node reboots during normal operations to reduce the window in which a poisoned sandbox state can be reloaded.
  • Monitor node mounts, especially for /dev/shm mounts that appear after a CRI‑O restart, as an indicator of potential container escape.

Generated by OpenCVE AI on September 30, 2026 at 13:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 12:00:00 +0000

Type Values Removed Values Added
Description A trust-boundary flaw in CRI-O's sandbox state persistence allows attacker-influenced pod metadata to overwrite CRI-O's own reserved sandbox bookkeeping; once reloaded as trusted after a restart, a later container recreate in that sandbox can expose a host-side runtime-management resource inside the container, enabling container escape.
Title Cri-o: cri-o: sandbox state poisoning via pod annotations may expose runtime socket
First Time appeared Redhat
Redhat openshift
Weaknesses CWE-501
CPEs cpe:/a:redhat:openshift:4
Vendors & Products Redhat
Redhat openshift
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Redhat Openshift
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-30T11:49:20.363Z

Reserved: 2026-07-13T11:29:50.979Z

Link: CVE-2026-62146

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-30T12:17:13.617

Modified: 2026-09-30T12:17:13.617

Link: CVE-2026-62146

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T13:30:17Z

Weaknesses