GPU VulnDB

Database/Container, Kubernetes & orchestration

CRI-O: attacker-influenced pod metadata poisons sandbox bookkeeping and enables container escape

CVSS 7.8CVE-2026-62146Container, Kubernetes & orchestrationcurated

Impact

A workload that can influence its own pod metadata can overwrite the fields CRI-O reserves for its internal sandbox bookkeeping. CRI-O reloads that persisted state as trusted after a restart, and a subsequent container recreate inside the same sandbox can then surface a host-side runtime-management resource inside the container, which Red Hat describes as enabling container escape. On a GPU node that is a tenant breaking out of its pod onto a host that also holds other tenants' GPU contexts, device plugin sockets and fabric access. The scope change in the CVSS vector reflects exactly that crossing. The attack needs a CRI-O restart in between, which is routine on nodes that get upgraded or drained, so the window is not exotic.

Who can reach it

Local: a user who can create or control a pod spec on the node (any tenant with namespace-level pod creation, on OpenShift or any CRI-O cluster) plus a CRI-O restart and a container recreate in the same sandbox. Authentication to the cluster API is required; no host access is needed beforehand.

What to do

Apply the CRI-O update from the Red Hat advisory for your OpenShift 4 stream (see GHSA-6wmc-5877-hgc9 for the upstream patched releases). Updating CRI-O restarts the container runtime on the node, so GPU workloads on that node are interrupted - in practice this is a rolling drain and reboot per node through the machine config operator, which on a full GPU fleet means scheduling capacity loss rather than a quick daemon bounce. Until patched, restrict who can set arbitrary pod metadata (admission policy on annotations and labels) on nodes that host untrusted tenants.

References

Related entries

All Container, Kubernetes & orchestration entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.