Threats Tagged 'cve-2026-18107'
View all threats tagged with 'cve-2026-18107'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-18107'
Click on any threat for detailed analysis and mitigation recommendations
A flaw was found in CRIU's handling of restartable sequences (rseq) during checkpoint/restore. (CVE-2026-18107)CVE-2026-18107 0 A vulnerability in CRIU's handling of restartable sequences (rseq) during checkpoint/restore allows a malicious process inside a container to spoof process credentials saved in the checkpoint image. This can lead to elevated capabilities and zeroed UIDs/GIDs on restore. However, exploitation requires root or cluster-admin privileges to trigger checkpoint/restore, and multiple container security mechanisms limit practical impact. Join the discussion | GCVE Database | 07/28/2026, 21:31:31 UTC Added: 07/28/2026, 23:50:10 UTC |
CVE-2026-18107: Improper Privilege Management in Red Hat Red Hat Enterprise Linux 10CVE-2026-18107 0 A flaw was found in CRIU's handling of restartable sequences (rseq) during checkpoint/restore. A malicious process inside a container can register an rseq critical section that hijacks CRIU's parasite code injection during checkpoint, allowing it to spoof the process credentials saved in the checkpoint image. On restore, the container process gains elevated capabilities and zeroed UIDs/GIDs. The practical impact on Red Hat products is limited by several factors: checkpoint/restore requires root privileges (podman) or cluster-admin RBAC (OpenShift) to trigger and cannot be initiated from within the container itself; on OpenShift prior to 4.17 the feature required explicit opt-in, and on 4.17+ the kubelet checkpoint API RBAC is not configured by default; OpenShift enforces user namespaces by default for regular workloads (hostUsers is gated behind admin-only SCCs), which makes the spoofed capabilities namespace-scoped and ineffective for privilege escalation; SELinux type enforcement (container_t) blocks privilege transitions independently of capabilities; seccomp filters persist through checkpoint/restore and cannot be corrupted via the parasite; and kernel mount namespace ownership checks on RHEL 9/10 kernels prevent mount-based container escape even with spoofed capabilities. Join the discussion | CVE Database V5 | 07/28/2026, 18:32:37 UTC Added: 07/28/2026, 19:07:41 UTC |
Showing 1 to 2 of 2 results