chiprook
← Security
SecuritySeptember 30, 2026, 19:07

Kubernetes checkpoint restore bypasses destination security policy

Flaws in containerd and CRI-O let a container restored from a checkpoint run as root with full capabilities and no seccomp filter, ignoring the orchestrator's policy. containerd fixed it in 2.2.7 and 2.3.4 by disabling the path by default.

Kubernetes checkpoint restore bypasses destination security policy
#Kubernetes#Containerd#CRI-O
Read next
Software

Kubernetes 1.36 restores a lost guarantee for database backups

Software

113 Void Linux Packages Orphaned Following AI Policy Dispute

Security

Check Point: 77% of firms rewrote security strategy for AI, only 26% can enforce it

Security

Gyazo breach exposes 23.6M user records via server flaw