CVE-2026-15801

Red Hat · OpenShift Container Platform 4

A path traversal vulnerability exists in the CRI-O container checkpoint and restore feature, potentially allowing unauthorized host filesystem operations.

Executive summary

A critical path traversal vulnerability in Red Hat OpenShift Container Platform 4 may allow privileged users to manipulate the host filesystem via malicious container checkpoint archives.

Vulnerability

This vulnerability, classified as a path traversal (CWE-22), occurs due to insufficient validation of restore metadata within the CRI-O component. Successful exploitation requires an attacker with sufficient privileges to enable the container checkpoint and restore functionality, which is not active by default, and trigger restoration from untrusted content.

Business impact

The vulnerability carries a CVSS score of 8.0, indicating high severity. A successful exploit could lead to full compromise of the host system, resulting in unauthorized data access, system integrity loss, or complete service disruption. Given the potential for container breakout, the risk to multi-tenant environments is significant.

Remediation

Immediate Action: Apply the latest security updates provided by Red Hat to patch the CRI-O component.

Proactive Monitoring: Audit container runtime logs for unusual checkpoint or restore activities and monitor for unauthorized access attempts to the underlying host filesystem.

Compensating Controls: Disable the container checkpoint and restore feature if it is not required for operational workflows to eliminate the attack surface.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Organizations utilizing Red Hat OpenShift should prioritize reviewing their container runtime configurations to determine if the checkpoint and restore feature is enabled. If in use, apply the vendor-provided patches immediately to mitigate the risk of host-level unauthorized operations.

More Red Hat CVEs all →

History

  1. Collected by CVE Brief via github
  2. Held for re-check analysis graded thin
  3. Analyst report written
  4. Analyst report updated

Sources