Incorrect authorization in containerd - CVE-2026-53492
Published: June 19, 2026
Vulnerability details
The vulnerability allows a remote user to bypass device allocation controls and inject arbitrary CDI configuration into a restored container.
The vulnerability exists due to improper input validation and incorrect authorization in containerd CRI checkpoint restore handling when restoring a container from an untrusted checkpoint image. A remote user can create a pod and restore it from a crafted checkpoint image to bypass device plugin enforcement and inject arbitrary CDI edits into the restored container.
Only nodes with CDI enabled and a matching host CDI specification for the requested device are vulnerable.
Affected software
Fedora
docker-buildkit
docker-buildx
containerd
docker-compose
How to mitigate CVE-2026-53492
docker-buildkit - update to 0.32.1-1.fc45
docker-buildx - update to 0.36.0-1.fc45
containerd - update to 2.3.2-1.fc45
docker-compose - update to 5.3.0-1.fc45