Database/Container, Kubernetes & orchestration
CRI-O: attacker-influenced pod metadata poisons sandbox bookkeeping and enables container escape
Impact
A workload that can influence its own pod metadata can overwrite the fields CRI-O reserves for its internal sandbox bookkeeping. CRI-O reloads that persisted state as trusted after a restart, and a subsequent container recreate inside the same sandbox can then surface a host-side runtime-management resource inside the container, which Red Hat describes as enabling container escape. On a GPU node that is a tenant breaking out of its pod onto a host that also holds other tenants' GPU contexts, device plugin sockets and fabric access. The scope change in the CVSS vector reflects exactly that crossing. The attack needs a CRI-O restart in between, which is routine on nodes that get upgraded or drained, so the window is not exotic.
Who can reach it
Local: a user who can create or control a pod spec on the node (any tenant with namespace-level pod creation, on OpenShift or any CRI-O cluster) plus a CRI-O restart and a container recreate in the same sandbox. Authentication to the cluster API is required; no host access is needed beforehand.
What to do
Apply the CRI-O update from the Red Hat advisory for your OpenShift 4 stream (see GHSA-6wmc-5877-hgc9 for the upstream patched releases). Updating CRI-O restarts the container runtime on the node, so GPU workloads on that node are interrupted - in practice this is a rolling drain and reboot per node through the machine config operator, which on a full GPU fleet means scheduling capacity loss rather than a quick daemon bounce. Until patched, restrict who can set arbitrary pod metadata (admission policy on annotations and labels) on nodes that host untrusted tenants.
References
Related entries
- Traefik: Authentication bypass via path traversal in ReplacePathRegexCVE-2026-65600 · TraefikHigh
- Submariner operator: long-lived broker service account token exposed in the Submariner CRCVE-2026-66782 · Submariner operator (broker service account token in the Submariner CR)High
- Traefik: rewrite-target path traversal bypasses authentication on protected routersCVE-2026-67309 · Traefik (Kubernetes Ingress NGINX provider, RewriteTarget middleware)High
- etcd: Gateway can be pointed at itself, causing an infinite loop and control-plane DoSCVE-2020-15114 · etcdHigh
- Argo CD: Directory traversal via Helm charts discloses credentials from other Applications' value filesCVE-2022-24348 · Argo CDHigh
- Argo CD: Path traversal plus improper access control in the repo-serverCVE-2022-24730 · Argo CDHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.