UNIX symbolic link following in containerd - CVE-2026-53489
Published: June 19, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information from the host.
The vulnerability exists due to symlink following in the CRI plugin checkpoint restore handling of container.log when restoring a checkpoint image. A remote attacker can supply a crafted checkpoint image containing a symlinked path to disclose sensitive information from the host.
The issue can expose host files via kubectl logs.
Affected software
Fedora
containerd
How to mitigate CVE-2026-53489
containerd - update to 2.3.2-1.fc45