SB2026092801 - Fedora 46 update for cri-o1.36



SB2026092801 - Fedora 46 update for cri-o1.36

Published: September 28, 2026 Updated: September 30, 2026

Security Bulletin ID SB2026092801
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Denial of service

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Input validation error (CVE-ID: CVE-2026-17113)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause a denial of service.

The vulnerability exists due to improper input validation in CRI-O daemon when processing a crafted OCI image with a malformed environment variable entry. A local privileged user can supply a specially crafted OCI image to cause a denial of service.

This only occurs when no environment variables are set in the container spec, and the normal Kubernetes API path does not trigger the issue.


Remediation

Install update from vendor's website.