---
id: CVE-2026-76061
title: A flaw was found in CRI-O's `bind_mount_prefix` handling
summary: >-
  A flaw was found in CRI-O's `bind_mount_prefix` handling. When configured with
  a non-empty `bind_mount_prefix`, a malicious container or local attacker could
  use a Container Runtime Interface (CRI) hostPath containing an intermediate
  abs…
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:L'
cwe:
  - CWE-59
vendor: Red Hat
product: cri-o
affected:
  - cri-o < 1.34.14
  - cri-o >= 1.35.0 < 1.35.9
  - cri-o >= 1.36.0 < 1.36.6
  - cri-o >= 1.37.0 < 1.37.1
  - cri-o (all versions)
  - openshift/ose-rhel-coreos-8 (all versions)
  - openshift/ose-rhel-coreos-9 (all versions)
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T20:17:29.123'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-76061'
references:
  - url: 'https://access.redhat.com/security/cve/CVE-2026-76061'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2520330'
    label: secalert@redhat.com
  - url: >-
      https://github.com/cri-o/cri-o/commit/01f90366dc8c8db0df32b4aae7fd067c1eddbb70
    label: secalert@redhat.com
  - url: >-
      https://github.com/cri-o/cri-o/commit/6d08a9a60ecfabdb3cbea0c8d698e31f1f01cb40
    label: secalert@redhat.com
  - url: >-
      https://github.com/cri-o/cri-o/commit/d6f58973acfcae93ecc039e0297fbe5f2548b46b
    label: secalert@redhat.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T20:16:42.472Z'
---

## Overview

A flaw was found in CRI-O's `bind_mount_prefix` handling. When configured with a non-empty `bind_mount_prefix`, a malicious container or local attacker could use a Container Runtime Interface (CRI) hostPath containing an intermediate absolute symlink. This could cause the bind mount source to resolve outside the intended prefixed root, potentially leading to unauthorized access to files or privilege escalation on the host system.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
