PatchSiren cyber security CVE debrief
CVE-2026-15801 Red Hat CVE debrief
A vulnerability was found in CRI-O related to the container checkpoint and restore feature. When CRI-O is configured to restore containers from checkpoint archives, insufficient validation of restore metadata may allow a user with sufficient privileges to perform unintended operations on the host filesystem. Successful exploitation requires that container checkpoint and restore functionality is enabled, which is not the default configuration. An attacker must also be able to trigger restoration of a container from untrusted checkpoint content.
- Vendor
- Red Hat
- Product
- Red Hat OpenShift Container Platform 4
- CVSS
- HIGH 8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-21
- Original CVE updated
- 2026-09-21
- Advisory published
- 2026-09-21
- Advisory updated
- 2026-09-21
Who should care
Defenders responsible for containerized environments using CRI-O, particularly those with container checkpoint and restore functionality enabled, should assess exposure and verify configurations.
Why it matters
Defenders should prioritize verifying CRI-O configurations and ensuring that only trusted checkpoint content is used to prevent unintended operations on the host filesystem.
- Verify CRI-O configurations to prevent unintended operations.
- Monitor container checkpoint and restore operations for potential exploitation attempts.
- Ensure trusted checkpoint content is used to prevent exploitation.
Technical summary
Insufficient validation of restore metadata in CRI-O's container checkpoint and restore feature may allow a user with sufficient privileges to perform unintended operations on the host filesystem. This vulnerability requires that container checkpoint and restore functionality is enabled, which is not the default configuration. An attacker must also be able to trigger restoration of a container from untrusted checkpoint content. Defenders should prioritize verifying CRI-O configurations, reviewing container checkpoint and restore functionality, and ensuring that only trusted checkpoint content is used.
Defensive priority
Defenders should prioritize verifying CRI-O configurations, reviewing container checkpoint and restore functionality, and ensuring that only trusted checkpoint content is used.
Recommended defensive actions
- Verify CRI-O configurations to ensure container checkpoint and restore functionality is not enabled by default.
- Review and monitor container checkpoint and restore operations to detect potential exploitation attempts.
- Ensure that only trusted checkpoint content is used and validate restore metadata.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
The CVE record and NVD entry provide details on the vulnerability in CRI-O related to container checkpoint and restore feature. Additional information on affected versions and remediation is limited. Defenders should verify CRI-O configurations, review container checkpoint and restore functionality, and ensure that only trusted checkpoint content is used. The vulnerability allows a user with sufficient privileges to perform unintended operations on the host filesystem if container checkpoint and restore functionality is enabled.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-15801 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-15801
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-15801 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-15801
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/security/cve/CVE-2026-15801
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.