CVE-2026-94603

Public on 2026-10-01
Modified on 2026-10-01
Description
A flaw was found in Podman. When a container image with checkpoint annotations is executed using the podman run command, Podman treats the image as a restored checkpoint and ignores user-specified sandboxing options, such as dropped privileges. An attacker can exploit this issue by enticing a user to run a specially crafted image, leading to a container sandbox bypass and potential execution with elevated system privileges.
Severity
Important severity
Important
See what this means
CVSS v3 Base Score
8.6
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2023 buildah Not Affected
Amazon Linux 2027 Preview buildah Not Affected

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 8.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H