GPU VulnDB

Database/Container, Kubernetes & orchestration

CRI-O: symlink in hostPath escapes bind_mount_prefix root and exposes host files

CVSS 5.5CVE-2026-76061Container, Kubernetes & orchestrationcurated

Impact

On nodes where CRI-O is configured with a non-empty bind_mount_prefix, a pod spec containing a hostPath with an intermediate absolute symlink can make the bind-mount source resolve outside the intended prefixed root. The container then gets a mount of a host path the operator believed was out of reach, which Red Hat describes as potentially leading to unauthorized file access or privilege escalation on the host. On a shared GPU node this is a tenant-to-host boundary: the same kubelet and CRI-O serve every pod on the box, so one tenant able to set hostPath reaches files belonging to the node and to its neighbours. The CVSS vector marks it high complexity and high privilege required, which matches the preconditions - the non-default bind_mount_prefix setting plus the ability to submit a hostPath mount.

Who can reach it

A workload author who can create a pod with a hostPath volume (so, authenticated against the cluster API with permission to set hostPath, or an already-compromised container with local access to the CRI socket), on a node whose CRI-O config sets a non-empty bind_mount_prefix. Default deployments that leave bind_mount_prefix empty are not in the described configuration.

What to do

Update CRI-O to a build carrying the upstream fix commits, or take the OpenShift Container Platform 4 update Red Hat ships for this CVE; the advisory pages are the authority on which stream contains it. CRI-O is the node's container runtime, so applying it means restarting crio and in practice draining the node first - running containers do not survive the runtime change cleanly on a GPU node that has in-flight jobs. Until then, the configuration-side mitigation that follows from the description is to leave bind_mount_prefix empty and to block hostPath volumes with admission control.

References

Related entries

All Container, Kubernetes & orchestration entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.