CVE-2026-92574 (CVSS 8.8) affects CRI-O checkpoint restore and can let an attacker authorized to create pods restore a malicious checkpoint whose process retains its original Linux security state instead of receiving the destination pod's security context. Preserved state may include credentials, capabilities, no_new_privs, seccomp filters, namespaces, and other execution attributes, allowing effective kernel restrictions to diverge from approved Kubernetes YAML policy. The issue affects CRI-O 1.34 and later and Red Hat OpenShift Container Platform 4.17 and later where checkpoint restore is enabled; no active exploitation has been confirmed.
Checkpoint archives created through CRIU should be treated as privileged, security-sensitive artifacts because they can encapsulate a process's full runtime state. Organizations should disable checkpoint restore where it is not required, restrict pod creation and checkpoint-restore permissions, accept checkpoint images only from trusted and verified registries, and validate effective post-restore credentials, capabilities, and seccomp policy. Administrators should deploy vendor-provided fixed CRI-O builds once available; comparable containerd restore functionality has been disabled by default where destination-policy enforcement could not be assured.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Earlier in September 2026, a containerd advisory described a comparable checkpoint-restoration policy-enforcement risk. Containerd disabled one restore path by default because it could not guarantee that destination policy would be enforced.
Fixes for CVE-2026-92574 were applied to the CRI-O 1.34.x, 1.35.x, and 1.36.x branches, but the fixed builds had not yet been released. Anticipated fixed versions were identified as 1.34.14, 1.35.9, and 1.36.6.
CVE-2026-92574 was documented as a CRI-O checkpoint-restore flaw in which malicious checkpoint data can retain credentials, capabilities, no_new_privs, and seccomp state rather than applying the destination Kubernetes pod security context. Exploitation requires permission to create pods and enabled checkpoint restoration.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
6 references tracked. Mallory keeps watching after this page renders.
linuxsecurity.com
Open sourcelinuxsecurity.com
Open sourcelinuxsecurity.com
Open sourcelinuxsecurity.com
Open sourcelinuxsecurity.com
Open sourcethreataft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.