Improper privilege management in containerd - #VU146902

 

Improper privilege management in containerd - #VU146902

Published: September 4, 2026


Vulnerability identifier: #VU146902
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-269
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to execute processes with elevated privileges.

The vulnerability exists due to improper privilege management in the containerd CRI checkpoint restore implementation when restoring an untrusted checkpoint through the CreateContainer API. A local user can create a container using a crafted checkpoint image to execute processes with elevated privileges.

The issue affects Linux systems with CRI checkpoint restore enabled. CRI status reporting reflects the requested configuration rather than the actual restored process state.


Affected software

containerd

Remediation

Install security update from vendor's website.

containerd - addressed in versions 2.2.7, 2.3.4

External References

Related Security Bulletins