Database/Container, Kubernetes & orchestration
CRI-O: symlink in hostPath escapes bind_mount_prefix root and exposes host files
Impact
On nodes where CRI-O is configured with a non-empty bind_mount_prefix, a pod spec containing a hostPath with an intermediate absolute symlink can make the bind-mount source resolve outside the intended prefixed root. The container then gets a mount of a host path the operator believed was out of reach, which Red Hat describes as potentially leading to unauthorized file access or privilege escalation on the host. On a shared GPU node this is a tenant-to-host boundary: the same kubelet and CRI-O serve every pod on the box, so one tenant able to set hostPath reaches files belonging to the node and to its neighbours. The CVSS vector marks it high complexity and high privilege required, which matches the preconditions - the non-default bind_mount_prefix setting plus the ability to submit a hostPath mount.
Who can reach it
A workload author who can create a pod with a hostPath volume (so, authenticated against the cluster API with permission to set hostPath, or an already-compromised container with local access to the CRI socket), on a node whose CRI-O config sets a non-empty bind_mount_prefix. Default deployments that leave bind_mount_prefix empty are not in the described configuration.
What to do
Update CRI-O to a build carrying the upstream fix commits, or take the OpenShift Container Platform 4 update Red Hat ships for this CVE; the advisory pages are the authority on which stream contains it. CRI-O is the node's container runtime, so applying it means restarting crio and in practice draining the node first - running containers do not survive the runtime change cleanly on a GPU node that has in-flight jobs. Until then, the configuration-side mitigation that follows from the description is to leave bind_mount_prefix empty and to block hostPath volumes with admission control.
References
Related entries
- runc (linux.resources.devices cgroup list handling): MULTI-TENANT DEVICE ISOLATION: runc implemented theNCVD-2020-005-runc-linux-resources-devices-cgr · runc (linux.resources.devices cgroup list handling)Medium
- etcd (write-ahead log, user authentication entries): CONTROL-PLANE CREDENTIALS AT REST IN CLEARTEXT: etcd writes theNCVD-2020-006-etcd-write-ahead-log-user-authen · etcd (write-ahead log, user authentication entries)Medium
- containerd (default mounts, /sys/devices/virtual/powercap RAPL): Containers get read access to Intel RAPL powerNCVD-2023-009-containerd-default-mounts-sys-de · containerd (default mounts, /sys/devices/virtual/powercap RAPL)Medium
- Kubernetes (kubelet/kube-proxy): Node's 127.0.0.1-bound services reachable from adjacent hosts and podsCVE-2020-8558 · Kubernetes (kubelet/kube-proxy)Medium
- Cilium: Ingress NetworkPolicies not enforced for pod traffic to L7 servicesCVE-2026-33726 · CiliumMedium
- Istio: serviceAccounts and notServiceAccounts in AuthorizationPolicy are evaluated incorrectlyCVE-2026-39350 · IstioMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.