Medium severity5.5NVD Advisory· Published Oct 6, 2026
CVE-2026-76061
CVE-2026-76061
Description
A flaw was found in CRI-O's bind_mount_prefix handling. When configured with a non-empty bind_mount_prefix, a malicious container or local attacker could use a Container Runtime Interface (CRI) hostPath containing an intermediate absolute symlink. This could cause the bind mount source to resolve outside the intended prefixed root, potentially leading to unauthorized access to files or privilege escalation on the host system.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
5- access.redhat.com/security/cve/CVE-2026-76061nvd
- bugzilla.redhat.com/show_bug.cginvd
- github.com/cri-o/cri-o/commit/01f90366dc8c8db0df32b4aae7fd067c1eddbb70nvd
- github.com/cri-o/cri-o/commit/6d08a9a60ecfabdb3cbea0c8d698e31f1f01cb40nvd
- github.com/cri-o/cri-o/commit/d6f58973acfcae93ecc039e0297fbe5f2548b46bnvd
News mentions
0No linked articles in our index yet.