top of page
perceptive_background_267k.jpg

A flaw was found in CRIU's handling of restartable sequences (rseq) during checkpoint/restore. A malicious process inside a container can register an rseq criti…

Published:

28 July 2026 at 00:00:00

Alert date:

28 July 2026 at 22:07:40

Source:

nvd.nist.gov

Click to open the original link from this advisory

Cloud & Virtualization, Operating Systems, Identity & Access

CVE-2026-18107 is a flaw in CRIU (Checkpoint/Restore In Userspace) related to its handling of restartable sequences (rseq) during checkpoint/restore operations. A malicious process inside a container can register an rseq critical section that hijacks CRIU's parasite code injection during checkpoint, enabling it to spoof process credentials in the checkpoint image. Upon restore, the container process gains elevated capabilities and zeroed UIDs/GIDs, potentially enabling privilege escalation. The practical impact on Red Hat products is significantly mitigated by multiple layered defenses: checkpoint/restore requires root or cluster-admin privileges and cannot be triggered from within the container; OpenShift enforces user namespaces by default limiting capability scope; SELinux type enforcement (container_t) independently blocks privilege transitions; seccomp filters are preserved through checkpoint/restore; and RHEL 9/10 kernel mount namespace ownership checks prevent mount-based escapes. The vulnerability affects CRIU and has implications for container runtimes like Podman and orchestration platforms like OpenShift.

Technical details

Mitigation steps:

Affected products:

CRIU
Podman
Red Hat OpenShift
RHEL 9
RHEL 10

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page