VYPR
Medium severity6.0NVD Advisory· Published Aug 24, 2026

CVE-2026-17113

CVE-2026-17113

Description

A flaw was found in CRI-O's container-creation environment-variable handling (mergeEnvs in server/utils.go, consumed by setupContainerEnvironmentAndWorkdir in server/container_create.go). When a CreateContainer request supplies a nil CRI Envs field, CRI-O falls back to using the target OCI image's config.Env entries unfiltered, in contrast to the normal merge path, which validates each entry for a key=value form before use. An OCI image whose config.Env contains an entry with no = character (e.g. a bare NOEQUALS string) causes CRI-O to split that entry into a single-element slice and then index its second element, which is out of range. This triggers an unrecovered Go runtime panic in the crio daemon process, crashing it and terminating the container-runtime service for all workloads on the node until it is restarted.

Affected products

2

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.