SB2026090408 - Improper privilege management in containerd
Published: September 4, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper privilege management (CVE-ID: N/A)
CWE-ID: CWE-269 - Improper Privilege Management
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to execute processes with elevated privileges.
The vulnerability exists due to improper privilege management in the containerd CRI checkpoint restore implementation when restoring an untrusted checkpoint through the CreateContainer API. A local user can create a container using a crafted checkpoint image to execute processes with elevated privileges.
The issue affects Linux systems with CRI checkpoint restore enabled. CRI status reporting reflects the requested configuration rather than the actual restored process state.
Remediation
Install update from vendor's website.