PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-15801 Red Hat CVE debrief

A vulnerability was found in CRI-O related to the container checkpoint and restore feature. When CRI-O is configured to restore containers from checkpoint archives, insufficient validation of restore metadata may allow a user with sufficient privileges to perform unintended operations on the host filesystem. Successful exploitation requires that container checkpoint and restore functionality is enabled, which is not the default configuration. An attacker must also be able to trigger restoration of a container from untrusted checkpoint content.

Vendor
Red Hat
Product
Red Hat OpenShift Container Platform 4
CVSS
HIGH 8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-21
Original CVE updated
2026-09-21
Advisory published
2026-09-21
Advisory updated
2026-09-21

Who should care

Defenders responsible for containerized environments using CRI-O, particularly those with container checkpoint and restore functionality enabled, should assess exposure and verify configurations.

Why it matters

Defenders should prioritize verifying CRI-O configurations and ensuring that only trusted checkpoint content is used to prevent unintended operations on the host filesystem.

  • Verify CRI-O configurations to prevent unintended operations.
  • Monitor container checkpoint and restore operations for potential exploitation attempts.
  • Ensure trusted checkpoint content is used to prevent exploitation.

Technical summary

Insufficient validation of restore metadata in CRI-O's container checkpoint and restore feature may allow a user with sufficient privileges to perform unintended operations on the host filesystem. This vulnerability requires that container checkpoint and restore functionality is enabled, which is not the default configuration. An attacker must also be able to trigger restoration of a container from untrusted checkpoint content. Defenders should prioritize verifying CRI-O configurations, reviewing container checkpoint and restore functionality, and ensuring that only trusted checkpoint content is used.

Defensive priority

Defenders should prioritize verifying CRI-O configurations, reviewing container checkpoint and restore functionality, and ensuring that only trusted checkpoint content is used.

Recommended defensive actions

  • Verify CRI-O configurations to ensure container checkpoint and restore functionality is not enabled by default.
  • Review and monitor container checkpoint and restore operations to detect potential exploitation attempts.
  • Ensure that only trusted checkpoint content is used and validate restore metadata.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.

Evidence notes

The CVE record and NVD entry provide details on the vulnerability in CRI-O related to container checkpoint and restore feature. Additional information on affected versions and remediation is limited. Defenders should verify CRI-O configurations, review container checkpoint and restore functionality, and ensure that only trusted checkpoint content is used. The vulnerability allows a user with sufficient privileges to perform unintended operations on the host filesystem if container checkpoint and restore functionality is enabled.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-15801 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-15801

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-15801 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-15801

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.