Skip to finding
important · Privilege escalation

A pod creator can make CRI-O restore a checkpoint with privileges forbidden by the destination pod policy.

Affects

CRI-O, a Linux container runtime used by Kubernetes and OpenShift nodes.

Where checkpoint restore and CRIU are enabled, saved credentials, capabilities, no_new_privs and seccomp state can replace the requested securityContext. The restored process can therefore start as root with full capabilities and no seccomp. A fix is announced, but pre-fix checkpoint images remain accepted.

Detail and 2 sources
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Tuesday, September 22, 2026