Kubernetes checkpoint restore bypasses destination security policy
Flaws in containerd and CRI-O let a container restored from a checkpoint run as root with full capabilities and no seccomp filter, ignoring the orchestrator's policy. containerd fixed it in 2.2.7 and 2.3.4 by disabling the path by default.
- Restoring a process from a checkpoint skips destination policy translation
- containerd: a container can run as root without seccomp despite policy
- Fixed in containerd 2.2.7 and 2.3.4, path disabled by default
- CVE-2026-92574 records the same issue in CRI-O
Read next
Software