<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:kubernetes:cri-O:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3akubernetescri-o/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 30 Sep 2026 12:34:37 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3akubernetescri-o/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>CRI-O Sandbox State Persistence Trust-Boundary Vulnerability</title><link>https://feed.craftedsignal.io/briefs/2026-09-crio-sandbox-escape/</link><pubDate>Wed, 30 Sep 2026 12:34:37 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-crio-sandbox-escape/</guid><description>A trust-boundary vulnerability in CRI-O allows an attacker to manipulate pod metadata to overwrite sandbox bookkeeping, enabling container escape via host-side resource mounting upon container recreation.</description><content:encoded><![CDATA[<p>CVE-2026-62146 describes a critical trust-boundary flaw within the CRI-O container runtime related to its sandbox state persistence mechanism. An attacker capable of influencing pod metadata can overwrite CRI-O's internally reserved sandbox bookkeeping information. This state is serialized and subsequently treated as trusted by the runtime upon a process restart or daemon reload. When the affected sandbox is triggered to recreate a container, the compromised state data directs the runtime to inadvertently mount sensitive host-side runtime-management resources directly into the container filesystem. This transition from untrusted pod input to trusted runtime configuration facilitates a container escape, granting the attacker access to host-level resources and providing a pathway for privilege escalation. This vulnerability poses a significant risk in multi-tenant environments where pod metadata may be partially accessible or influenced by non-privileged users.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2026-62146 allows an attacker to break out of the container isolation boundary. By accessing host-side runtime management resources, an attacker can achieve full host compromise, potentially leading to unauthorized data access, lateral movement within the cluster, and persistent control over the underlying node. This vulnerability affects all environments running vulnerable versions of CRI-O.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Update the CRI-O runtime to the latest patched version once released by the vendor to address the sandbox state persistence flaw.</li>
<li>Audit Kubernetes pod specifications to ensure that metadata fields are restricted and cannot be manipulated by untrusted users or processes.</li>
<li>Monitor node-level logs for unusual container lifecycle events, such as repeated unexpected container recreations or initialization patterns associated with unauthorized configuration changes.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>container-security</category><category>privilege-escalation</category><category>runtime-security</category></item></channel></rss>