GCP-2026-051

Imported from official source

Security notice

Cybersecurity Classified by Officially

2026-08-04 Update: The VMware patch release version is 1.33.1200, not 1.33.1100 as stated in the initial bulletin.

The following vulnerabilities have been discovered in containerd (the GDC container runtime). These vulnerabilities allow attackers with permissions to create Pods to bypass Kubernetes security boundaries and perform host compromise, cache poisoning, and denial of service. While these vulnerabilities are critical in the context of containerd, the requirement to have cluster privileges to create Pods to exploit them means they are considered High according to GDC (software only) vulnerability classification.

  • CVE-2026-50195 (Critical): containerd's CRI checkpoint import process fails to validate image references. An attacker with permissions to create Pods can use a crafted checkpoint image to poison the node's local image cache, causing other pods to use a malicious image.
  • CVE-2026-53488 (Critical): CRI plugin propagates labels from an image config to a container without validation. This may result in executing an arbitrary command on the host.
  • CVE-2026-53492 (Critical): CRI implementation improperly trusts Container Device Interface (CDI) annotations during container restoration. This allows an attacker to inject arbitrary CDI configurations (such as host mounts and device nodes) into restored containers, bypassing resource allocation and device plugin enforcement.
  • CVE-2026-53489 (High): CRI plugin restores container.log without validating a symlinked path, allowing an attacker to read arbitrary host files via kubectl logs.
  • CVE-2026-47262 (Moderate): A vulnerability in containerd allows a maliciously crafted image to cause memory exhaustion (DoS) of the containerd process.
  • This is an extract. The publication continues at the source.

    Read the original at the source: https://docs.cloud.google.com/support/bulletins/index#gcp-2026-051

    Officially imported this from Google’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

    This publication has changed since it was first published

    5 versions recorded. The original is kept in full — nothing is overwritten.

    1. v5 imported change on current
    2. v4 imported change on
    3. v3 imported change on
    4. v2 imported change on
    5. v1 as first published on

    Provenance

    Organization
    Google — imported from official source
    Official source
    https://cloud.google.com/feeds/google-cloud-security-bulletins.xml RSS
    Imported
    September 15, 2026 20:57
    Versions
    5 recorded
    Identity
    tag:google.com,2016:google-cloud-security-bulletins#gcp-2026-051

    Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.