Incorrect authorization in containerd - CVE-2026-53492
Published: June 19, 2026
containerd
Detailed vulnerability description
The vulnerability allows a remote user to bypass device allocation controls and inject arbitrary CDI configuration into a restored container.
The vulnerability exists due to improper input validation and incorrect authorization in containerd CRI checkpoint restore handling when restoring a container from an untrusted checkpoint image. A remote user can create a pod and restore it from a crafted checkpoint image to bypass device plugin enforcement and inject arbitrary CDI edits into the restored container.
Only nodes with CDI enabled and a matching host CDI specification for the requested device are vulnerable.