CVE-2026-17113

Description

A flaw was found in CRI-O's container-creation environment-variable handling (mergeEnvs in server/utils.go, consumed by setupContainerEnvironmentAndWorkdir in server/container_create.go). When a CreateContainer request supplies a nil CRI Envs field, CRI-O falls back to using the target OCI image's config.Env entries unfiltered, in contrast to the normal merge path, which validates each entry for a key=value form before use. An OCI image whose config.Env contains an entry with no = character (e.g. a bare NOEQUALS string) causes CRI-O to split that entry into a single-element slice and then index its second element, which is out of range. This triggers an unrecovered Go runtime panic in the crio daemon process, crashing it and terminating the container-runtime service for all workloads on the node until it is restarted.

Statement

A flaw was found in CRI-O, a container runtime. Under a specific internal condition, CRI-O skips validating whether a container image's environment variable entries are properly formatted before using them. If an image contains a malformed environment variable, CRI-O crashes while processing it.

Common Vulnerability Scoring System (CVSS) Score Details

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

The following CVSS metrics and score provided are preliminary and subject to review.

CVSS v3 Score Breakdown

Red HatNVDcve.org
Base Score6N/A6
Attack VectorLocalN/ALocal
Attack ComplexityLowN/ALow
Privileges RequiredHighN/AHigh
User InteractionNoneN/ANone
ScopeChangedN/AChanged
ConfidentialityNoneN/ANone
Integrity ImpactNoneN/ANone
Availability ImpactHighN/AHigh

Vector

Red Hat: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H

cve.org: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H

Understanding the Weakness (CWE)

Other

Technical Impact: Varies by Context

Acknowledgements

Red Hat would like to thank Arpit Jain for reporting this issue.

Frequently Asked Questions

Want to get errata notifications? Sign up here.