PT-2026-51058 · Unknown+3 · Kubernetes Containerd+3

·

CVE-2026-53492

·

Published

2026-06-18

·

Updated

2026-08-18

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions containerd versions prior to 2.1.9 containerd versions prior to 2.2.5 containerd versions prior to 2.3.2
Description The CRI implementation improperly trusts Container Device Interface (CDI) annotations found within untrusted checkpoint image metadata during container restoration. Instead of relying solely on the pod's create-time specification, the system preserves CDI-related annotations from the checkpoint archive. This allows a user with pod creation permissions to bypass Kubernetes resource allocation and device plugin enforcement by injecting arbitrary CDI edits, such as device nodes and host mounts, into the restored container. This issue requires CDI to be enabled on the node and the presence of a matching host CDI specification for the requested device.
Recommendations Update to version 2.1.9. Update to version 2.2.5. Update to version 2.3.2. Restrict the restoration of containers from untrusted checkpoint images. Remove or temporarily relocate host CDI specifications from the /etc/cdi and /var/run/cdi directories if CDI capabilities are not utilized on the node.

Exploit

Fix

DoS

RCE

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-90170
CVE-2026-53492
GHSA-33VJ-92QQ-66HC
GO-2026-5064
OPENSUSE-SU-2026:11102-1
OPENSUSE-SU-2026:21072-1
OPENSUSE-SU-2026:21483-1
RHSA-2026:15862
RHSA-2026:32963
RHSA-2026:32974
USN-8472-1
USN-8473-1

Affected Products

Linuxmint
Red Os
Ubuntu
Kubernetes Containerd