Skip to content
Red HatCVE-2026-15809

Red Hat CRI-O: format string

High7.8CVE-2026-15809 · Published Jul 15, 2026 · updated Sep 25, 2026

A flaw was found in CRI-O. The fix for a previous vulnerability (CVE-2022-4318) was incorrect, allowing it to be bypassed. An attacker capable of setting environment variables on a container can inject a newline character into the HOME environment variable. This issue allows the addition of arbitrary lines into /etc/passwd by use of a specially crafted environment variable.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Confidential Compute Attestation
Product
all versionsNo fix yet
Red Hat OpenShift Container Platform 4
Product
all versionsNo fix yet
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat AAP Gateway Envoy proxy configuration: authentication bypass by spoofing
High8.2Jul 15
Red Hat samba: denial of service
Medium6.1Jul 15
Red Hat OpenShift GitOps: denial of service
High7.7Jul 15
A flaw was found in libsoup's WebSocket implementation
High7.5Jul 14
Red Hat libsoup: denial of service
High7.5Jul 14
Red Hat libsoup: denial of service
Medium5.9Jul 14

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.