All CVEs
Vulnerability intelligence

CVE-2026-53492

containerd containerd CWE-20

containerd is an open-source container runtime. In Versions prior to 2.3.2, 2.2.5 and 2.1.9, the CRI implementation improperly trusts Container Device Interface (CDI) annotations found within untrusted checkpoint image metadata during container restoration. When restoring a container from a checkpoint, containerd preserves CDI-related annotations from the checkpoint archive rather than relying solely on the pod's create-time specification. This allows a user with pod creation permissions to bypass standard Kubernetes resource allocation and device plugin enforcement, injecting arbitrary CDI edits (such as device nodes and host mounts) into the restored container.

CVSS Score
8.4
High
EPSS — Exploit Probability
0.3%
Riskier than 28% of all CVEs · checked 2026-09-21
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
unknown
Check vendor advisories
NVD entry

1 article across 1 outlet · first covered Jun 24, 2026 · latest Jun 24, 2026

Coverage timeline

Related CVEs — containerd