VYPR
Medium severity5.5NVD Advisory· Published Oct 6, 2026

CVE-2026-76061

CVE-2026-76061

Description

A flaw was found in CRI-O's bind_mount_prefix handling. When configured with a non-empty bind_mount_prefix, a malicious container or local attacker could use a Container Runtime Interface (CRI) hostPath containing an intermediate absolute symlink. This could cause the bind mount source to resolve outside the intended prefixed root, potentially leading to unauthorized access to files or privilege escalation on the host system.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.