PT-2026-51058 · Unknown · Kubernetes Containerd

Published

2026-06-19

·

Updated

2026-06-22

·

CVE-2026-53492

CVSS v4.0

8.4

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions containerd versions prior to 2.1.9 containerd versions prior to 2.2.5 containerd versions prior to 2.3.2
Description The CRI implementation improperly trusts Container Device Interface (CDI) annotations found within untrusted checkpoint image metadata during container restoration. Instead of relying solely on the pod's create-time specification, the system preserves CDI-related annotations from the checkpoint archive. This allows a user with pod creation permissions to bypass Kubernetes resource allocation and device plugin enforcement by injecting arbitrary CDI edits, such as device nodes and host mounts, into the restored container. This issue requires CDI to be enabled on the node and the presence of a matching host CDI specification for the requested device.
Recommendations Update to version 2.1.9. Update to version 2.2.5. Update to version 2.3.2. Restrict the restoration of containers from untrusted checkpoint images. Remove or temporarily relocate host CDI specifications from the /etc/cdi and /var/run/cdi directories if CDI capabilities are not utilized on the node.

Fix

Incorrect Authorization

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53492
GHSA-33VJ-92QQ-66HC

Affected Products

Kubernetes Containerd