← All Advisories

CVE-2026-15809

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-15809

Key Details

CVECVE-2026-15809
CVSS Score / Version7.8 (High) / CVSS v3.1
Updated2026-10-01
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productssee table below
Classified asCWE-134 (Use of Externally-Controlled Format String)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Red HatRed Hat OpenShift Container Platform 4.12
Red HatRed Hat OpenShift Container Platform 4.13
Red HatRed Hat OpenShift Container Platform 4.14
Red HatRed Hat OpenShift Container Platform 4.15
Red HatRed Hat OpenShift Container Platform 4.16
Red HatRed Hat OpenShift Container Platform 4.17
Red HatRed Hat OpenShift Container Platform 4.18
Red HatRed Hat OpenShift Container Platform 4.19
Red HatRed Hat OpenShift Container Platform 4
Red HatRed Hat OpenShift Container Platform 4.20
Red HatRed Hat OpenShift Container Platform 4.21
Red HatRed Hat OpenShift Container Platform 4.22
Red HatConfidential Compute Attestation
SubsystemsGeneral OT
SectorsMultiple

What to Know

A flaw was found in CRI-O. The fix for a previous vulnerability (CVE-2022-4318) was incorrect, allowing it to be bypassed. An attacker capable of setting environment variables on a container can inject a newline character into the HOME environment variable. This issue allows the addition of arbitrary lines into /etc/passwd by use of a specially crafted environment variable. (NVD)

What to Do

Monitor Red Hat's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-15809
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-15809