{"id":"CVE-2026-15809","title":"A flaw was found in CRI-O","summary":"A flaw was found in CRI-O. The fix for a previous vulnerability (CVE-2022-4318) was incorrect, allowing it to be bypassed. An attacker capable of setting environment variables on a container can inject a newline character into the HOME e…","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-134","CWE-116"],"vendor":"Red Hat","product":"cri-o","affected":["cri-o (all versions)","cri-o (all versions)","cri-o (all versions)","cri-o (all versions)","cri-o (all versions)","openshift-sandboxed-containers/osc-monitor-rhel9 (all versions)","openshift4/cnf-tests-rhel8 (all versions)","openshift4/ztp-site-generate-rhel8 (all versions)"],"patched":["openshift_container_platform 4.16","openshift_container_platform 4.19","openshift_container_platform 4.20","openshift_container_platform 4.21","openshift_container_platform 4.22"],"published":"2026-07-15","updated":"2026-09-17","sourceUpdated":"2026-09-17T12:17:24.363","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-15809","references":[{"url":"https://access.redhat.com/errata/RHSA-2026:57361","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:60444","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:60449","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:60452","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:62548","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:65838","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:65906","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:66385","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2026-15809","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2500846","label":"secalert@redhat.com"},{"url":"https://github.com/cri-o/cri-o/pull/6450","label":"secalert@redhat.com"},{"url":"https://github.com/cri-o/cri-o/pull/6524","label":"secalert@redhat.com"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-15809.json"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-15809"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-15809"}],"tags":["nvd","cve.org","csaf","vex","red-hat"],"epss":0.00176,"epssPercentile":0.07402,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-07-15T13:06:08.620102Z"},"ingestedAt":"2026-09-10T09:45:12.032Z","slug":"CVE-2026-15809","body":"## Overview\n\nA flaw was found in CRI-O. The fix for a previous vulnerability (CVE-2022-4318) was incorrect, allowing it to be bypassed. An attacker capable of setting environment variables on a container can inject a newline character into the HOME environment variable. This issue allows the addition of arbitrary lines into /etc/passwd by use of a specially crafted environment variable.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **RHSA-2026:62548** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.16 · released 2026-09-10 · [advisory](https://access.redhat.com/errata/RHSA-2026:62548)\n- **RHSA-2026:60452** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.19 · released 2026-09-02 · [advisory](https://access.redhat.com/errata/RHSA-2026:60452)\n- **RHSA-2026:60444** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.20 · released 2026-09-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:60444)\n- **RHSA-2026:60449** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.21 · released 2026-09-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:60449)\n- **RHSA-2026:57361** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.22 · released 2026-08-25 · [advisory](https://access.redhat.com/errata/RHSA-2026:57361)\n- **Red Hat VEX** · Important · affected: Confidential Compute Attestation, Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat OpenShift Container Platform 4, Confidential Compute Attestation · updated 2026-09-17 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-15809.json)\n- **RHSA-2026:65906** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.12 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:65906)\n- **RHSA-2026:65838** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.13 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:65838)\n- **RHSA-2026:66385** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.18 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:66385)","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}