CVE-2026-15809 Details
Description
A flaw was found in CRI-O. The fix for a previous vulnerability (CVE-2022-4318) was incorrect, allowing it to be bypassed. An attacker capable of setting environment variables on a container can inject a newline character into the HOME environment variable. This issue allows the addition of arbitrary lines into /etc/passwd by use of a specially crafted environment variable.
A vulnerability exists in CRI-O due to an incorrect fix for a previous issue (CVE-2022-4318), allowing the vulnerability to be bypassed. An attacker who can set environment variables in a container can inject a newline character into the HOME variable. This injection enables the addition of arbitrary lines to the /etc/passwd file by using a specially crafted environment variable. The vulnerability is present in CRI-O versions prior to 1.26.0.
Users can upgrade to CRI-O versions 1.26.0 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 15, 2026CISA-ADP
Assessed Jul 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-116 | Improper Encoding or Escaping of Output | CISA-ADP |
| CWE-134 | Use of Externally-Controlled Format String | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| CRI-O | < 1.25 |
CPE
Remediation
| |
| Red Hat Confidential Compute Attestation | All versions |
CPE
Remediation
| |
| Red Hat OpenShift Container Platform | All versions |
CPE
Remediation
| |
Change History
13 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 25, 2026 | CVE Modified | [email protected] |
| Sep 24, 2026 | CVE Modified | [email protected] |
| Sep 17, 2026 | CVE Modified | [email protected] |
| Sep 17, 2026 | CVE Modified | [email protected] |
| Sep 10, 2026 | CVE Modified | [email protected] |
| Sep 2, 2026 | CVE Modified | [email protected] |
| Sep 1, 2026 | CVE Modified | [email protected] |
| Sep 1, 2026 | CVE Modified | [email protected] |
| Aug 25, 2026 | CVE Modified | [email protected] |
| Jul 16, 2026 | CVE Modified | [email protected] |
| Jul 15, 2026 | CVE Modified | CISA-ADP |
| Jul 15, 2026 | CVE Modified | [email protected] |
| Jul 15, 2026 | New CVE Received | [email protected] |
Volerion