CVE-2026-76061

high

Description

A flaw was found in CRI-O's `bind_mount_prefix` handling. When configured with a non-empty `bind_mount_prefix`, a malicious container or local attacker could use a Container Runtime Interface (CRI) hostPath containing an intermediate absolute symlink. This could cause the bind mount source to resolve outside the intended prefixed root, potentially leading to unauthorized access to files or privilege escalation on the host system.

References

https://github.com/cri-o/cri-o/commit/d6f58973acfcae93ecc039e0297fbe5f2548b46b

https://github.com/cri-o/cri-o/commit/6d08a9a60ecfabdb3cbea0c8d698e31f1f01cb40

https://github.com/cri-o/cri-o/commit/01f90366dc8c8db0df32b4aae7fd067c1eddbb70

https://bugzilla.redhat.com/show_bug.cgi?id=2520330

https://access.redhat.com/security/cve/CVE-2026-76061

Details

Source: Mitre, NVD

Published: 2026-10-06

Updated: 2026-10-06

Risk Information

CVSS v2

Base Score: 4.3

Vector: CVSS2#AV:N/AC:H/Au:M/C:P/I:P/A:P

Severity: Medium

CVSS v3

Base Score: 7.8

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Severity: High