PT-2026-50900 · Unknown+3 · Kubernetes Containerd+3

·

CVE-2026-50195

·

Published

2026-06-19

·

Updated

2026-08-18

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions containerd versions prior to 2.3.2 containerd versions prior to 2.2.5 containerd versions prior to 2.1.9 containerd versions prior to 2.0.10 containerd versions prior to 1.7.33
Description The CRI checkpoint import process fails to validate image references specified within a checkpoint image's configuration. An attacker with permissions to create pods can use a crafted checkpoint image to force the system to pull a malicious image and assign it an arbitrary local tag, poisoning the node's local image cache. If other pods on the same node use the poisoned tag with an IfNotPresent or Never pull policy, they will execute the malicious image instead of the legitimate one, allowing the attacker to execute arbitrary code under the victim pod's identity. Additionally, some related issues can lead to host-root command execution during restore.
Recommendations Update to version 2.3.2. Update to version 2.2.5. Update to version 2.1.9. Update to version 2.0.10. Update to version 1.7.33. Only allow trusted images to be pulled.

Exploit

Fix

DoS

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-90164
CVE-2026-50195
GHSA-CVXM-645Q-P574
GO-2026-5338
OPENSUSE-SU-2026:11102-1
OPENSUSE-SU-2026:21072-1
OPENSUSE-SU-2026:21483-1
RHSA-2026:35111
USN-8472-1
USN-8473-1

Affected Products

Linuxmint
Red Os
Ubuntu
Kubernetes Containerd