What is CVE-2026-18107?
A vulnerability has been found in CRIU's handling of restartable sequences (rseq) during checkpoint/restore. A malicious process inside a container can hijack CRIU's parasite code injection during checkpoint, allowing it to spoof the saved process credentials. It is recommended to update CRIU to the latest patched version to mitigate this issue.
Azərbaycanca: CRIU-da checkpoint/restore zamanı restartable sequences (rseq) bölmələrinin işlənməsində zəiflik aşkarlanıb. Konteyner daxilindəki zərərli proses, checkpoint zamanı CRIU-nun `parasite code` inyeksiyasını ələ keçirərək, saxlanılan proses etimadnamələrini saxtalaşdıra bilər. Təsirə məruz qalmamaq üçün CRIU-nu bu problemi aradan qaldıran ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: shared vendor: Red Hat
FAQ1
What risk does CVE-2026-18107 pose regarding CRIU's handling of restartable sequences (rseq)?
This vulnerability allows a malicious process inside a container to hijack CRIU's parasite code injection during checkpoint, enabling it to spoof the saved process credentials.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.