CVE-2026-62146
Description
A trust-boundary flaw in CRI-O's sandbox state persistence allows attacker-influenced pod metadata to overwrite CRI-O's own reserved sandbox bookkeeping; once reloaded as trusted after a restart, a later container recreate in that sandbox can expose a host-side runtime-management resource inside the container, enabling container escape.
Statement
This affects CRI-O versions that persist reserved sandbox metadata together with untrusted pod annotations/labels without validating or namespacing them separately and that reload this state as trusted after a restart, including products that bundle CRI-O as their runtime (e.g., OpenShift Container Platform nodes); exploitation requires pod-creation access plus a subsequent CRI-O restart/node reboot and container recreate, so affected-version and exposure-window details will be confirmed once upstream triage completes
Mitigation
There is no complete workaround; until a fix is available, administrators should restrict who can create/update pods and set arbitrary annotations via RBAC/admission policy, minimize unnecessary CRI-O restarts or node reboots and monitor for anomalous container mounts (e.g. under /dev/shm) following runtime restarts, then apply the vendor patch once released.
Common Vulnerability Scoring System (CVSS) Score Details
Info alert:Important note
CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).
The following CVSS metrics and score provided are preliminary and subject to review.
CVSS v3 Score Breakdown
| Red Hat | NVD | cve.org | |
|---|---|---|---|
| Base Score | 7.8 | N/A | 7.8 |
| Attack Vector | Local | N/A | Local |
| Attack Complexity | High | N/A | High |
| Privileges Required | Low | N/A | Low |
| User Interaction | None | N/A | None |
| Scope | Changed | N/A | Changed |
| Confidentiality | High | N/A | High |
| Integrity Impact | High | N/A | High |
| Availability Impact | High | N/A | High |
Vector
Red Hat: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
cve.org: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Understanding the Weakness (CWE)
Access Control
Technical Impact: Bypass Protection Mechanism
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.