{
  "threat_severity" : "Important",
  "public_date" : "2026-07-15T10:18:17Z",
  "bugzilla" : {
    "description" : "github.com/cri-o/cri-o: Fix Bypass for CVE-2022-4318 — /etc/passwd Injection via HOME env",
    "id" : "2500846",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2500846"
  },
  "cvss3" : {
    "cvss3_base_score" : "7.8",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
    "status" : "verified"
  },
  "cwe" : "CWE-134",
  "details" : [ "A flaw was found in CRI-O. The fix for a previous vulnerability (CVE-2022-4318) was incorrect, allowing it to be bypassed. An attacker capable of setting environment variables on a container can inject a newline character into the HOME environment variable. This issue allows the addition of arbitrary lines into /etc/passwd by use of a specially crafted environment variable.", "A flaw was found in CRI-O. The fix for a previous vulnerability (CVE-2022-4318) was incorrect, allowing it to be bypassed. An attacker capable of setting environment variables on a container can inject a newline character into the HOME environment variable. This issue allows the addition of arbitrary lines into /etc/passwd by use of a specially crafted environment variable." ],
  "statement" : "This Important flaw in CRI-O allows for arbitrary line injection into a container's `/etc/passwd` file. An attacker capable of setting container environment variables can bypass a previous fix (CVE-2022-4318) by supplying a real newline character in the `HOME` environment variable, potentially leading to privilege escalation within the affected container. This risk is present in environments where untrusted users can influence container environment variable settings.",
  "acknowledgement" : "Red Hat would like to thank Nebojša Jaćović (Independent Security Researcher) for reporting this issue.",
  "affected_release" : [ {
    "product_name" : "Red Hat OpenShift Container Platform 4.19",
    "release_date" : "2026-09-02T00:00:00Z",
    "advisory" : "RHSA-2026:60452",
    "cpe" : "cpe:/a:redhat:openshift:4.19::el9",
    "package" : "cri-o-0:1.32.13-11.rhaos4.19.git089e95c.el9"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4.20",
    "release_date" : "2026-09-01T00:00:00Z",
    "advisory" : "RHSA-2026:60444",
    "cpe" : "cpe:/a:redhat:openshift:4.20::el9",
    "package" : "cri-o-0:1.33.13-5.rhaos4.20.git7ebc848.el9"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4.21",
    "release_date" : "2026-09-01T00:00:00Z",
    "advisory" : "RHSA-2026:60449",
    "cpe" : "cpe:/a:redhat:openshift:4.21::el9",
    "package" : "cri-o-0:1.34.11-4.rhaos4.21.git358c4b4.el9"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4.22",
    "release_date" : "2026-08-25T00:00:00Z",
    "advisory" : "RHSA-2026:57361",
    "cpe" : "cpe:/a:redhat:openshift:4.22::el9",
    "package" : "cri-o-0:1.35.6-5.rhaos4.22.git41f610b.el9"
  } ],
  "package_state" : [ {
    "product_name" : "Confidential Compute Attestation",
    "fix_state" : "Affected",
    "package_name" : "openshift-sandboxed-containers/osc-monitor-rhel9",
    "cpe" : "cpe:/a:redhat:confidential_compute_attestation:1"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Affected",
    "package_name" : "openshift4/cnf-tests-rhel8",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Will not fix",
    "package_name" : "openshift4/ztp-site-generate-rhel8",
    "cpe" : "cpe:/a:redhat:openshift:4"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-15809\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-15809\nhttps://github.com/cri-o/cri-o/pull/6450\nhttps://github.com/cri-o/cri-o/pull/6524" ],
  "name" : "CVE-2026-15809",
  "mitigation" : {
    "value" : "Restrict access to users who can create or modify container workloads through appropriate RBAC permissions, apply security controls such as Security Context Constraints (SCCs) to limit privilege escalation, and enforce policies to run containers with reduced privileges (for example, as non-root) to reduce the impact of potential exploitation. Enable SELinux on affected nodes and consider admission controls to prevent potentially unsafe workload configurations.",
    "lang" : "en:us"
  },
  "csaw" : false
}