PT-2026-107188 · Red Hat · Red Hat Openshift Container Platform 4

CVE-2026-76061

·

Publicado

2026-10-06

·

Atualizado

2026-10-06

CVSS v3.1

5.5

Média

VetorAV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:L
A flaw was found in CRI-O's bind mount prefix handling. When configured with a non-empty bind mount prefix, a malicious container or local attacker could use a Container Runtime Interface (CRI) hostPath containing an intermediate absolute symlink. This could cause the bind mount source to resolve outside the intended prefixed root, potentially leading to unauthorized access to files or privilege escalation on the host system.

Correção

Link Following

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-76061

Produtos afetados

Red Hat Openshift Container Platform 4