{"id":"CVE-2026-53492","title":"github.com/containerd/containerd: containerd: Security bypass via Container Device Interface (CDI) annotation smuggling during checkpoint r…","summary":"A flaw was found in containerd, an open-source container runtime. The Container Runtime Interface (CRI) implementation, which allows Kubernetes to interact with container runtimes, improperly trusts Container Device Interface (CDI) annotat…","severity":"high","cvss":8.2,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N","cvssSource":"vendor","cwe":["CWE-807","CWE-20","CWE-863"],"vendor":"Red Hat","product":"Red Hat Openshift Data Foundation 4.20","affected":["assisted_installer_for_red_hat_openshift_container_platform 2","confidential_compute_attestation","deployment_validation_operator","exploit_intelligence","kernel_module_management_operator_for_red_hat_openshift","machine_deletion_remediation_operator","mcp_server_for_red_hat_openshift","migration_toolkit_for_virtualization","multicluster_engine_for_kubernetes","node_healthcheck_operator","openshift_developer_tools_and_services","openshift_lightspeed","openshift_pipelines","openshift_serverless","openshift_service_mesh 2","pen_drive_powered_by_red_hat_lightspeed","power_monitoring_for_red_hat_openshift","advanced_cluster_management_for_kubernetes 2","ansible_automation_platform 2","ceph_storage 6","ceph_storage 9","openshift_ai_rhoai","openshift_container_platform 4","openshift_gitops","trusted_artifact_signer","multicluster_global_hub 1.4.9","multicluster_global_hub 1.6.5","multicluster_global_hub 1.7.3","multicluster_global_hub 1.8.2","openshift_api_for_data_protection 1.3","openshift_api_for_data_protection 1.4","openshift_api_for_data_protection 1.5","advanced_cluster_management_for_kubernetes 2.13","advanced_cluster_security 4.9","advanced_cluster_security_for_kubernetes 4.10","hardened_images","openshift_dev_spaces 3.30","openshift_data_foundation 4.19","openshift_data_foundation 4.20","multicluster_global_hub 1.5.3"],"patched":["multicluster_global_hub 1.4.9","multicluster_global_hub 1.6.5","multicluster_global_hub 1.7.3","multicluster_global_hub 1.8.2","openshift_api_for_data_protection 1.3","openshift_api_for_data_protection 1.4","openshift_api_for_data_protection 1.5","advanced_cluster_management_for_kubernetes 2.13","advanced_cluster_security 4.9","advanced_cluster_security_for_kubernetes 4.10","hardened_images","openshift_dev_spaces 3.30","openshift_data_foundation 4.19","openshift_data_foundation 4.20","multicluster_global_hub 1.5.3"],"published":"2026-07-01","updated":"2026-09-21","sourceUpdated":"2026-09-21T15:44:08+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-53492.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-53492.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-53492"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2496130"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-53492"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53492"},{"url":"https://github.com/containerd/containerd/security/advisories/GHSA-33vj-92qq-66hc"},{"url":"https://access.redhat.com/errata/RHSA-2026:41030"},{"url":"https://access.redhat.com/errata/RHSA-2026:44622"},{"url":"https://access.redhat.com/errata/RHSA-2026:47149"},{"url":"https://access.redhat.com/errata/RHSA-2026:53530"},{"url":"https://access.redhat.com/errata/RHSA-2026:52946"},{"url":"https://access.redhat.com/errata/RHSA-2026:51033"},{"url":"https://access.redhat.com/errata/RHSA-2026:59467"},{"url":"https://access.redhat.com/errata/RHSA-2026:66022"},{"url":"https://access.redhat.com/errata/RHSA-2026:36873"},{"url":"https://access.redhat.com/errata/RHSA-2026:48872"},{"url":"https://access.redhat.com/errata/RHSA-2026:48913"},{"url":"https://access.redhat.com/errata/RHSA-2026:32963"},{"url":"https://access.redhat.com/errata/RHSA-2026:32974"},{"url":"https://access.redhat.com/errata/RHSA-2026:15862"},{"url":"https://access.redhat.com/errata/RHSA-2026:62260"},{"url":"https://access.redhat.com/errata/RHSA-2026:56366"},{"url":"https://access.redhat.com/errata/RHSA-2026:57013"},{"url":"https://access.redhat.com/errata/RHSA-2026:42852"},{"url":"https://github.com/advisories/GHSA-33vj-92qq-66hc"}],"tags":["csaf","vex","red-hat","ghsa","go"],"epss":0.00347,"epssPercentile":0.28277,"ecosystem":"go","ingestedAt":"2026-06-22T15:52:21.047Z","slug":"CVE-2026-53492","body":"## Overview\n\nA flaw was found in containerd, an open-source container runtime. The Container Runtime Interface (CRI) implementation, which allows Kubernetes to interact with container runtimes, improperly trusts Container Device Interface (CDI) annotations found within untrusted checkpoint image metadata during container restoration. This vulnerability enables a user with permissions to create pods to bypass standard Kubernetes resource allocation and device plugin enforcement. Consequently, an attacker can inject arbitrary CDI edits, such as device nodes and host mounts, into the restored container, potentially leading to unauthorized resource access or privilege escalation.\n\n## Vendor advisories\n\n- **RHSA-2026:41030** · Red Hat · fixed in: Multicluster Global Hub 1.4.9 · released 2026-07-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:41030)\n- **RHSA-2026:44622** · Red Hat · fixed in: Multicluster Global Hub 1.6.5 · released 2026-07-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:44622)\n- **RHSA-2026:47149** · Red Hat · fixed in: Multicluster Global Hub 1.7.3 · released 2026-07-28 · [advisory](https://access.redhat.com/errata/RHSA-2026:47149)\n- **RHSA-2026:53530** · Red Hat · fixed in: Multicluster Global Hub 1.7.3 · released 2026-08-11 · [advisory](https://access.redhat.com/errata/RHSA-2026:53530)\n- **RHSA-2026:52946** · Red Hat · fixed in: Multicluster Global Hub 1.8.2 · released 2026-08-10 · [advisory](https://access.redhat.com/errata/RHSA-2026:52946)\n- **RHSA-2026:51033** · Red Hat · fixed in: OpenShift API for Data Protection 1.3 · released 2026-08-06 · [advisory](https://access.redhat.com/errata/RHSA-2026:51033)\n- **RHSA-2026:59467** · Red Hat · fixed in: OpenShift API for Data Protection 1.4 · released 2026-08-25 · [advisory](https://access.redhat.com/errata/RHSA-2026:59467)\n- **RHSA-2026:66022** · Red Hat · fixed in: OpenShift API for Data Protection 1.5 · released 2026-09-09 · [advisory](https://access.redhat.com/errata/RHSA-2026:66022)\n- **RHSA-2026:36873** · Red Hat · fixed in: Red Hat Advanced Cluster Management for Kubernetes 2.13 · released 2026-07-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:36873)\n- **RHSA-2026:48872** · Red Hat · fixed in: Red Hat Advanced Cluster Security 4.9 · released 2026-07-30 · [advisory](https://access.redhat.com/errata/RHSA-2026:48872)\n- **RHSA-2026:48913** · Red Hat · fixed in: Red Hat Advanced Cluster Security for Kubernetes 4.10 · released 2026-07-30 · [advisory](https://access.redhat.com/errata/RHSA-2026:48913)\n- **Red Hat VEX** · Important · affected: Assisted Installer for Red Hat OpenShift Container Platform 2, Confidential Compute Attestation, Deployment Validation Operator, Exploit Intelligence, Kernel Module Management Operator for Red Hat Openshift, Machine Deletion Remediation Operator, … · no fix planned: Assisted Installer for Red Hat OpenShift Container Platform 2, Confidential Compute Attestation, MCP Server for Red Hat OpenShift, Migration Toolkit for Virtualization, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-53492.json)\n- **RHSA-2026:32963** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-06-29 · [advisory](https://access.redhat.com/errata/RHSA-2026:32963)\n\n**github.com/containerd/containerd: containerd: Security bypass via Container Device Interface (CDI) annotation smuggling during checkpoint restoration.** — rated Important by Red Hat. Released 2026-07-01, updated 2026-09-21.\n\nAffected:\n\n- Assisted Installer for Red Hat OpenShift Container Platform 2\n- Confidential Compute Attestation\n- Deployment Validation Operator\n- Exploit Intelligence\n- Kernel Module Management Operator for Red Hat Openshift\n- Machine Deletion Remediation Operator\n- MCP Server for Red Hat OpenShift\n- Migration Toolkit for Virtualization\n- Multicluster Engine for Kubernetes\n- Node HealthCheck Operator\n- OpenShift Developer Tools and Services\n- OpenShift Lightspeed\n- OpenShift Pipelines\n- OpenShift Serverless\n- OpenShift Service Mesh 2\n- Pen Drive Powered by Red Hat Lightspeed\n- Power monitoring for Red Hat OpenShift\n- Red Hat Advanced Cluster Management for Kubernetes 2\n- Red Hat Ansible Automation Platform 2\n- Red Hat Ceph Storage 6\n- Red Hat Ceph Storage 9\n- Red Hat OpenShift AI (RHOAI)\n- Red Hat OpenShift Container Platform 4\n- Red Hat OpenShift GitOps\n- Red Hat Trusted Artifact Signer\n\nFixed:\n\n- Multicluster Global Hub 1.4.9\n- Multicluster Global Hub 1.6.5\n- Multicluster Global Hub 1.7.3\n- Multicluster Global Hub 1.8.2\n- OpenShift API for Data Protection 1.3\n- OpenShift API for Data Protection 1.4\n- OpenShift API for Data Protection 1.5\n- Red Hat Advanced Cluster Management for Kubernetes 2.13\n- Red Hat Advanced Cluster Security 4.9\n- Red Hat Advanced Cluster Security for Kubernetes 4.10\n- Red Hat Hardened Images\n- Red Hat OpenShift Dev Spaces 3.30\n- Red Hat Openshift Data Foundation 4.19\n- Red Hat Openshift Data Foundation 4.20\n- Red Hat multicluster global hub 1.5.3\n\nNo fix planned:\n\n- Assisted Installer for Red Hat OpenShift Container Platform 2\n- Confidential Compute Attestation\n- MCP Server for Red Hat OpenShift\n- Migration Toolkit for Virtualization\n- Multicluster Engine for Kubernetes\n- OpenShift Service Mesh 2\n- Red Hat Advanced Cluster Management for Kubernetes 2\n- Red Hat Ansible Automation Platform 2\n- Red Hat OpenShift AI (RHOAI)\n- Red Hat OpenShift Container Platform 4\n- OpenShift Developer Tools and Services\n- Pen Drive Powered by Red Hat Lightspeed\n- Red Hat Ceph Storage 6\n- Red Hat Ceph Storage 9\n- Deployment Validation Operator\n- Exploit Intelligence\n- Kernel Module Management Operator for Red Hat Openshift\n- Machine Deletion Remediation Operator\n- Node HealthCheck Operator\n- OpenShift Lightspeed\n- OpenShift Pipelines\n- OpenShift Serverless\n- Power monitoring for Red Hat OpenShift\n- Red Hat OpenShift GitOps\n- Red Hat Trusted Artifact Signer\n\nNot affected:\n\n- Multicluster Global Hub 1.4.9\n- Multicluster Global Hub 1.6.5\n- Multicluster Global Hub 1.7.3\n- Multicluster Global Hub 1.8.2\n- OpenShift API for Data Protection 1.3\n- OpenShift API for Data Protection 1.4\n- OpenShift API for Data Protection 1.5\n- Red Hat Advanced Cluster Management for Kubernetes 2.13\n- Red Hat Advanced Cluster Security 4.9\n- Red Hat Advanced Cluster Security for Kubernetes 4.10\n\n## Remediation\n\nFor more details, see the Red Hat Advanced Cluster Management for Kubernetes documentation:\n\nhttps://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.13/html/multicluster_global_hub/index https://access.redhat.com/errata/RHSA-2026:41030\nFor more details, see the Red Hat Advanced Cluster Management for Kubernetes documentation:\n\nhttps://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.15/html/multicluster_global_hub/index https://access.redhat.com/errata/RHSA-2026:44622\nFor more details, see the Red Hat Advanced Cluster Management for Kubernetes documentation:\n\nhttps://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.16/html/multicluster_global_hub/index https://access.redhat.com/errata/RHSA-2026:47149\n\n## Package advisory (CVE-2026-53492)\n\nAffected packages:\n\n- `github.com/containerd/containerd/v2 >= 2.1.0, < 2.1.9`\n- `github.com/containerd/containerd/v2 >= 2.2.0, < 2.2.5`\n- `github.com/containerd/containerd/v2 >= 2.3.0, < 2.3.2`\n\nPatched in:\n\n- `github.com/containerd/containerd/v2 2.1.9`\n- `github.com/containerd/containerd/v2 2.2.5`\n- `github.com/containerd/containerd/v2 2.3.2`\n\nSource: https://github.com/advisories/GHSA-33vj-92qq-66hc","depth":"twilight","depthScore":45,"depthScoreParts":{"impact":45.1,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":5323,"id":"CVE-2026-53492","ts":1788887265952,"field":"cvss","old":null,"new":"8.2"},{"seq":4206,"id":"CVE-2026-53492","ts":1788886380535,"field":"cvss","old":"8.2","new":null},{"seq":3266,"id":"CVE-2026-53492","ts":1788883138608,"field":"cvss","old":null,"new":"8.2"}]}