{"id":"CVE-2026-53489","title":"github.com/containerd/containerd: containerd: Arbitrary host file read via symlink following in CRI checkpoint restore (CVE-2026-53489)","summary":"A flaw was found in containerd, an open-source container runtime. The Container Runtime Interface (CRI) plugin incorrectly restores container logs from a checkpoint image. This vulnerability, categorized as a Path Traversal (CWE-61), allow…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","cvssSource":"vendor","cwe":["CWE-59","CWE-61"],"vendor":"Red Hat","product":"Red Hat Openshift Data Foundation 4.20","affected":["exploit_intelligence","mcp_server_for_red_hat_openshift","migration_toolkit_for_virtualization","openshift_serverless","ceph_storage 6","ceph_storage 9","hardened_images","openshift_data_foundation 4.19","openshift_data_foundation 4.20"],"patched":["hardened_images","openshift_data_foundation 4.19","openshift_data_foundation 4.20"],"published":"2026-07-01","updated":"2026-09-18","sourceUpdated":"2026-09-18T07:37:20+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-53489.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-53489.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-53489"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2496129"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-53489"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53489"},{"url":"https://github.com/containerd/containerd/security/advisories/GHSA-rgh6-rfwx-v388"},{"url":"https://access.redhat.com/errata/RHSA-2026:32963"},{"url":"https://access.redhat.com/errata/RHSA-2026:32974"},{"url":"https://access.redhat.com/errata/RHSA-2026:15862"},{"url":"https://access.redhat.com/errata/RHSA-2026:56366"},{"url":"https://access.redhat.com/errata/RHSA-2026:57013"},{"url":"https://github.com/advisories/GHSA-rgh6-rfwx-v388"}],"tags":["csaf","vex","red-hat","ghsa","go"],"epss":0.00174,"epssPercentile":0.07159,"ecosystem":"go","ingestedAt":"2026-06-22T15:52:21.049Z","slug":"CVE-2026-53489","body":"## Overview\n\nA flaw was found in containerd, an open-source container runtime. The Container Runtime Interface (CRI) plugin incorrectly restores container logs from a checkpoint image. This vulnerability, categorized as a Path Traversal (CWE-61), allows an attacker to read arbitrary files on the host system by manipulating symlinked paths during the checkpoint restore process. This can lead to unauthorized information disclosure from the host.\n\n## Vendor advisories\n\n- **RHSA-2026:32963** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-06-29 · [advisory](https://access.redhat.com/errata/RHSA-2026:32963)\n- **RHSA-2026:32974** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-06-29 · [advisory](https://access.redhat.com/errata/RHSA-2026:32974)\n- **RHSA-2026:15862** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-05-09 · [advisory](https://access.redhat.com/errata/RHSA-2026:15862)\n- **RHSA-2026:56366** · Red Hat · fixed in: Red Hat Openshift Data Foundation 4.19 · released 2026-08-18 · [advisory](https://access.redhat.com/errata/RHSA-2026:56366)\n- **RHSA-2026:57013** · Red Hat · fixed in: Red Hat Openshift Data Foundation 4.20 · released 2026-08-19 · [advisory](https://access.redhat.com/errata/RHSA-2026:57013)\n- **Red Hat VEX** · Important · affected: Exploit Intelligence, MCP Server for Red Hat OpenShift, Migration Toolkit for Virtualization, OpenShift Serverless, Red Hat Ceph Storage 6, Red Hat Ceph Storage 9 · no fix planned: Exploit Intelligence, MCP Server for Red Hat OpenShift, Migration Toolkit for Virtualization, Red Hat Ceph Storage 6, … · updated 2026-09-18 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-53489.json)\n\n**github.com/containerd/containerd: containerd: Arbitrary host file read via symlink following in CRI checkpoint restore** — rated Important by Red Hat. Released 2026-07-01, updated 2026-09-18.\n\nAffected:\n\n- Exploit Intelligence\n- MCP Server for Red Hat OpenShift\n- Migration Toolkit for Virtualization\n- OpenShift Serverless\n- Red Hat Ceph Storage 6\n- Red Hat Ceph Storage 9\n\nFixed:\n\n- Red Hat Hardened Images\n- Red Hat Openshift Data Foundation 4.19\n- Red Hat Openshift Data Foundation 4.20\n\nNo fix planned:\n\n- Exploit Intelligence\n- MCP Server for Red Hat OpenShift\n- Migration Toolkit for Virtualization\n- Red Hat Ceph Storage 6\n- Red Hat Ceph Storage 9\n- OpenShift Serverless\n\nNot affected:\n\n- Red Hat Openshift Data Foundation 4.19\n- Red Hat Openshift Data Foundation 4.20\n- Assisted Installer for Red Hat OpenShift Container Platform 2\n- Confidential Compute Attestation\n- Deployment Validation Operator\n- Gatekeeper 3\n- Kernel Module Management Operator for Red Hat Openshift\n- Logging Subsystem for Red Hat OpenShift\n- Logical Volume Manager Storage\n- Machine Deletion Remediation Operator\n\n## Remediation\n\nFor details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/ https://access.redhat.com/errata/RHSA-2026:32963\nFor details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/ https://access.redhat.com/errata/RHSA-2026:32974\nFor details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/ https://access.redhat.com/errata/RHSA-2026:15862\n\nWorkarounds / mitigations:\n\n- For Red Hat OpenShift and layered products, CRI-O is the supported container runtime, so the vulnerable containerd CRI checkpoint-restore code path is not exercised during normal cluster operation. Customers should nevertheless apply Red Hat product errata as they become available to receive updates for affected operator, must-gather and tooling images that may bundle the containerd Go module.\n\nIf containerd is deployed as the container runtime with CRI checkpoint/restore enabled, disable check…\n\n## Package advisory (CVE-2026-53489)\n\nAffected packages:\n\n- `github.com/containerd/containerd/v2 >= 2.1.0, < 2.1.9`\n- `github.com/containerd/containerd/v2 >= 2.2.0, < 2.2.5`\n- `github.com/containerd/containerd/v2 >= 2.3.0, < 2.3.2`\n\nPatched in:\n\n- `github.com/containerd/containerd/v2 2.1.9`\n- `github.com/containerd/containerd/v2 2.2.5`\n- `github.com/containerd/containerd/v2 2.3.2`\n\nSource: https://github.com/advisories/GHSA-rgh6-rfwx-v388","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":206978,"id":"CVE-2026-53489","ts":1789749727411,"field":"cvss","old":null,"new":"6.5"},{"seq":206977,"id":"CVE-2026-53489","ts":1789749727411,"field":"severity","old":"high","new":"medium"}]}