{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/criu/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.8,"id":"CVE-2026-18107"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["CRIU","OpenShift","Podman","Kubelet"],"_cs_severities":["high"],"_cs_tags":["container-security","privilege-escalation","linux","cloud-native"],"_cs_type":"advisory","_cs_vendors":["Red Hat"],"content_html":"\u003cp\u003eA significant vulnerability, CVE-2026-18107, has been identified in CRIU's mechanism for handling restartable sequences (rseq) during checkpoint/restore operations. This flaw allows a malicious process executing within a container to exploit the checkpointing process itself. By registering a specially crafted rseq critical section, an attacker can hijack CRIU's parasite code injection, which occurs during a checkpoint. This manipulation enables the attacker to spoof the process credentials, including capabilities and user/group IDs, stored within the checkpoint image. When the container is subsequently restored from this compromised image, the malicious process inherits these falsified, elevated credentials, resulting in a privilege escalation within the container environment. While severe, the practical impact on Red Hat products like OpenShift and Podman is mitigated by several factors, including the requirement for root or cluster-admin privileges to initiate checkpoint/restore, default user namespaces, SELinux enforcement, persistent seccomp filters, and kernel mount namespace ownership checks in RHEL 9/10 kernels.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003e\u003cstrong\u003eInitial Access:\u003c/strong\u003e An attacker gains initial execution within a container, typically as a non-privileged user.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eCRIU Prerequisite Met:\u003c/strong\u003e The attacker (or an operator with elevated host privileges, e.g., root for Podman or cluster-admin for OpenShift) initiates a checkpoint operation on the target container using CRIU.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eMalicious rseq Registration:\u003c/strong\u003e The attacker's process within the container registers an \u003ccode\u003erseq\u003c/code\u003e critical section designed to intercept and manipulate CRIU's internal functions.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eParasite Code Hijack:\u003c/strong\u003e During the checkpoint phase, CRIU attempts to inject its parasite code into the target process. The previously registered malicious \u003ccode\u003erseq\u003c/code\u003e critical section hijacks this injection.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eCredential Spoofing:\u003c/strong\u003e The hijacked parasite code is then manipulated to forge and overwrite the process credentials (such as UIDs, GIDs, and capabilities) that CRIU normally saves into the checkpoint image.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eCheckpoint Image Corruption:\u003c/strong\u003e The corrupted checkpoint image, containing the falsified process credentials, is saved.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eRestore Operation:\u003c/strong\u003e A restore operation is performed, using the compromised checkpoint image, to restart the container.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ePrivilege Escalation:\u003c/strong\u003e Upon successful restoration, the container process resumes execution with the spoofed, elevated capabilities and zeroed UIDs/GIDs, effectively achieving privilege escalation within the container.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-18107 directly leads to privilege escalation within containerized environments. An attacker, initially operating with limited privileges inside a container, can gain elevated capabilities and zeroed UIDs/GIDs upon restore, potentially granting them near-root access within that container. While the vulnerability itself is critical, its practical impact on Red Hat products is significantly limited by multiple security layers. These mitigations include the requirement of root or cluster-admin privileges to trigger checkpoint/restore operations, OpenShift's default enforcement of user namespaces (which scopes capabilities), SELinux type enforcement, persistent seccomp filters, and kernel mount namespace ownership checks on RHEL 9/10, all of which aim to prevent container escapes or broad privilege escalations even if the initial credential spoofing occurs.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIf deploying CRIU in environments without the mitigations present in Red Hat products, immediately review and implement security controls that restrict checkpoint/restore operations to highly trusted administrators.\u003c/li\u003e\n\u003cli\u003eEnsure that container orchestration platforms, such as OpenShift, are configured with default user namespaces and robust RBAC policies that prevent non-administrative users from initiating checkpoint/restore operations, thereby mitigating the risk described in CVE-2026-18107.\u003c/li\u003e\n\u003cli\u003eVerify that SELinux policies are enforced in containerized environments to block unauthorized privilege transitions, even if capabilities are spoofed, as this provides a critical layer of defense against CVE-2026-18107.\u003c/li\u003e\n\u003cli\u003eConfirm that \u003ccode\u003eseccomp\u003c/code\u003e filters are active and persist through checkpoint/restore operations, as these can restrict syscalls and prevent exploitation attempts associated with CVE-2026-18107.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-28T19:22:43Z","date_published":"2026-07-28T19:22:43Z","id":"https://feed.craftedsignal.io/briefs/2026-07-criu-rseq-privesc/","summary":"A flaw, CVE-2026-18107, in CRIU's handling of restartable sequences (rseq) during checkpoint/restore allows a malicious process inside a container to hijack CRIU's parasite code injection, enabling the spoofing of process credentials in the checkpoint image and leading to elevated capabilities and zeroed UIDs/GIDs upon restore.","title":"CRIU Restartable Sequences Vulnerability Allows Container Privilege Escalation","url":"https://feed.craftedsignal.io/briefs/2026-07-criu-rseq-privesc/"}],"language":"en","title":"CraftedSignal Threat Feed - CRIU","version":"https://jsonfeed.org/version/1.1"}