Unknown · Kubernetes Containerd · CVE-2026-53489
**Name of the Vulnerable Software and Affected Versions**
containerd versions prior to 2.1.9
containerd versions prior to 2.2.5
containerd versions prior to 2.3.2
**Description**
A bug in the CRI plugin allows the restoration of `container.log` from a checkpoint image without validating a symlinked path. This can lead to an arbitrary file read on the host system when using `kubectl logs`.
**Recommendations**
Update to version 2.1.9.
Update to version 2.2.5.
Update to version 2.3.2.
Ensure that only trusted images and checkpoints are used.