Skip to content
Red HatCVE-2026-62146

A trust-boundary flaw in CRI-O's sandbox state persistence

High7.8CVE-2026-62146 · Published Sep 30, 2026

A trust-boundary flaw in CRI-O's sandbox state persistence allows attacker-influenced pod metadata to overwrite CRI-O's own reserved sandbox bookkeeping; once reloaded as trusted after a restart, a later container recreate in that sandbox can expose a host-side runtime-management resource inside the container, enabling container escape.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat OpenShift Container Platform 4
Product
all versionsNo fix yet
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat Enterprise Linux: request smuggling
Medium5.3Sep 30
Assisted Installer for Red Hat OpenShift Container Platform : path traversal
High7.3Sep 30
Red Hat rpm. RPMTAG_FILESIGNATURES: heap buffer overflow
High7.1Sep 30
Red Hat libsoup.: buffer overflow
High8.6Sep 29
Red Hat libsoup.: buffer overflow
High8.6Sep 29
Red Hat libsoup.: buffer overflow
High8.6Sep 29

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.