Skip to content
Critical Vulnerability in CRI-O Checkpoint Restore Exposes Kubernetes Clusters

Critical Vulnerability in CRI-O Checkpoint Restore Exposes Kubernetes Clusters

First seen 21 Sep 2026, 16:53 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 21, 2026 at 18:54 UTC
  • CVE-2026-92574 allows privilege escalation via malicious checkpointed containers.
  • Affected versions include CRI-O 1.34 and later, and OpenShift 4.17 onward.
  • Immediate action is required to mitigate risks, including disabling checkpoint restore.

A vulnerability identified as CVE-2026-92574 in CRI-O's checkpoint restore feature allows users to create pods from malicious checkpointed containers, bypassing Kubernetes security contexts. This flaw affects CRI-O versions 1.34 and later, with downstream impacts on Red Hat OpenShift Container Platform starting from version 4.17. The restored processes may retain sensitive credentials and capabilities, enabling potential privilege escalation and unauthorized access. Exploitation requires permission to create pods and active checkpoint restore functionality. Fixes are pending release, but immediate action is recommended for affected environments. Security measures include disabling checkpoint restore if not needed and restricting pod creation privileges. The vulnerability poses a high risk, particularly in shared cluster environments.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-21
CVE-2026-92574 published
A vulnerability in CRI-O's checkpoint restore feature was disclosed, affecting multiple versions and allowing privilege escalation.
access.redhat.com
2026-09-21
Red Packet Security reports on CVE-2026-92574
Red Packet Security highlights the high-impact nature of the vulnerability and the urgent need for action in affected clusters.
Redpacketsecurity

More articles in this cluster (2)

Following this threat?

Track Red Hat and CVE-2026-92574 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed