CVE-2026-18107

EUVD-2026-49986
A flaw was found in CRIU's handling of restartable sequences (rseq) during checkpoint/restore. A malicious process inside a container can register an rseq critical section that hijacks CRIU's parasite code injection during checkpoint, allowing it to spoof the process credentials saved in the checkpoint image. On restore, the container process gains elevated capabilities and zeroed UIDs/GIDs.

The practical impact on Red Hat products is limited by several factors: checkpoint/restore requires root privileges (podman) or cluster-admin RBAC (OpenShift) to trigger and cannot be initiated from within the container itself; on OpenShift prior to 4.17 the feature required explicit opt-in, and on 4.17+ the kubelet checkpoint API RBAC is not configured by default; OpenShift enforces user namespaces by default for regular workloads (hostUsers is gated behind admin-only SCCs), which makes the spoofed capabilities namespace-scoped and ineffective for privilege escalation; SELinux type enforcement (container_t) blocks privilege transitions independently of capabilities; seccomp filters persist through checkpoint/restore and cannot be corrupted via the parasite; and kernel mount namespace ownership checks on RHEL 9/10 kernels prevent mount-based container escape even with spoofed capabilities.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
HIGH
LOW
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 1.58%
Debian logo
Debian Releases
Debian Product
Codename
criu
bookworm
postponed
forky
4.2.1-1
fixed
sid
4.2.1-1
fixed
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
criu
bionic
needs-triage
jammy
needs-triage
noble
dne
resolute
needs-triage
xenial
needs-triage
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
crit
Amazon Linux 2023
0:3.17.1-1.amzn2023.0.4
fixed
criu
Amazon Linux 2023
0:3.17.1-1.amzn2023.0.4
fixed
criu-debuginfo
Amazon Linux 2023
0:3.17.1-1.amzn2023.0.4
fixed
criu-debugsource
Amazon Linux 2023
0:3.17.1-1.amzn2023.0.4
fixed
criu-devel
Amazon Linux 2023
0:3.17.1-1.amzn2023.0.4
fixed
criu-libs
Amazon Linux 2023
0:3.17.1-1.amzn2023.0.4
fixed
criu-libs-debuginfo
Amazon Linux 2023
0:3.17.1-1.amzn2023.0.4
fixed
criu-ns
Amazon Linux 2023
0:3.17.1-1.amzn2023.0.4
fixed
python3-criu
Amazon Linux 2023
0:3.17.1-1.amzn2023.0.4
fixed