


Perceptive Security
SOC/SIEM Consultancy

A flaw was found in CRIU's handling of restartable sequences (rseq) during checkpoint/restore. A malicious process inside a container can register an rseq criti…
Published:
27 juli 2026 om 22:00:00
Alert date:
28 juli 2026 om 20:07:40
Source:
nvd.nist.gov
Cloud & Virtualization, Operating Systems, Identity & Access
CVE-2026-18107 is a flaw in CRIU (Checkpoint/Restore In Userspace) related to its handling of restartable sequences (rseq) during checkpoint/restore operations. A malicious process inside a container can register an rseq critical section that hijacks CRIU's parasite code injection during checkpoint, enabling it to spoof process credentials in the checkpoint image. Upon restore, the container process gains elevated capabilities and zeroed UIDs/GIDs, potentially enabling privilege escalation. The practical impact on Red Hat products is significantly mitigated by multiple layered defenses: checkpoint/restore requires root or cluster-admin privileges and cannot be triggered from within the container; OpenShift enforces user namespaces by default limiting capability scope; SELinux type enforcement (container_t) independently blocks privilege transitions; seccomp filters are preserved through checkpoint/restore; and RHEL 9/10 kernel mount namespace ownership checks prevent mount-based escapes. The vulnerability affects CRIU and has implications for container runtimes like Podman and orchestration platforms like OpenShift.
Technical details
Mitigation steps:
Affected products:
CRIU
Podman
Red Hat OpenShift
RHEL 9
RHEL 10
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-18107
https://access.redhat.com/security/cve/CVE-2026-18107
https://bugzilla.redhat.com/show_bug.cgi?id=2508140
https://github.com/checkpoint-restore/criu/pull/3097
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
