{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2026-15809",
        "assignerOrgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
        "state": "PUBLISHED",
        "assignerShortName": "redhat",
        "dateReserved": "2026-07-15T09:57:48.452Z",
        "datePublished": "2026-07-15T12:32:42.587Z",
        "dateUpdated": "2026-09-01T19:55:44.952Z"
    },
    "containers": {
        "cna": {
            "title": "Github.com/cri-o/cri-o: fix bypass for cve-2022-4318 — /etc/passwd injection via home env",
            "metrics": [
                {
                    "other": {
                        "content": {
                            "value": "Important",
                            "namespace": "https://access.redhat.com/security/updates/classification/"
                        },
                        "type": "Red Hat severity rating"
                    }
                },
                {
                    "cvssV3_1": {
                        "attackComplexity": "LOW",
                        "attackVector": "LOCAL",
                        "availabilityImpact": "HIGH",
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH",
                        "confidentialityImpact": "HIGH",
                        "integrityImpact": "HIGH",
                        "privilegesRequired": "LOW",
                        "scope": "UNCHANGED",
                        "userInteraction": "NONE",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "format": "CVSS"
                }
            ],
            "descriptions": [
                {
                    "lang": "en",
                    "value": "A flaw was found in CRI-O. The fix for a previous vulnerability (CVE-2022-4318) was incorrect, allowing it to be bypassed. An attacker capable of setting environment variables on a container can inject a newline character into the HOME environment variable. This issue allows the addition of arbitrary lines into /etc/passwd by use of a specially crafted environment variable."
                }
            ],
            "affected": [
                {
                    "vendor": "Red Hat",
                    "product": "Red Hat OpenShift Container Platform 4.20",
                    "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
                    "packageName": "cri-o",
                    "defaultStatus": "affected",
                    "versions": [
                        {
                            "version": "0:1.33.13-5.rhaos4.20.git7ebc848.el9",
                            "lessThan": "*",
                            "versionType": "rpm",
                            "status": "unaffected"
                        }
                    ],
                    "cpes": [
                        "cpe:/a:redhat:openshift:4.20::el8",
                        "cpe:/a:redhat:openshift:4.20::el9"
                    ]
                },
                {
                    "vendor": "Red Hat",
                    "product": "Red Hat OpenShift Container Platform 4.21",
                    "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
                    "packageName": "cri-o",
                    "defaultStatus": "affected",
                    "versions": [
                        {
                            "version": "0:1.34.11-4.rhaos4.21.git358c4b4.el9",
                            "lessThan": "*",
                            "versionType": "rpm",
                            "status": "unaffected"
                        }
                    ],
                    "cpes": [
                        "cpe:/a:redhat:openshift:4.21::el9"
                    ]
                },
                {
                    "vendor": "Red Hat",
                    "product": "Red Hat OpenShift Container Platform 4.22",
                    "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
                    "packageName": "cri-o",
                    "defaultStatus": "affected",
                    "versions": [
                        {
                            "version": "0:1.35.6-5.rhaos4.22.git41f610b.el9",
                            "lessThan": "*",
                            "versionType": "rpm",
                            "status": "unaffected"
                        }
                    ],
                    "cpes": [
                        "cpe:/a:redhat:openshift:4.22::el8",
                        "cpe:/a:redhat:openshift:4.22::el9",
                        "cpe:/a:redhat:openshift_ironic:4.22::el9"
                    ]
                },
                {
                    "vendor": "Red Hat",
                    "product": "Confidential Compute Attestation",
                    "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
                    "packageName": "openshift-sandboxed-containers/osc-monitor-rhel9",
                    "defaultStatus": "affected",
                    "cpes": [
                        "cpe:/a:redhat:confidential_compute_attestation:1"
                    ]
                },
                {
                    "vendor": "Red Hat",
                    "product": "Red Hat OpenShift Container Platform 4",
                    "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
                    "packageName": "openshift4/cnf-tests-rhel8",
                    "defaultStatus": "affected",
                    "cpes": [
                        "cpe:/a:redhat:openshift:4"
                    ]
                },
                {
                    "vendor": "Red Hat",
                    "product": "Red Hat OpenShift Container Platform 4",
                    "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
                    "packageName": "openshift4/ztp-site-generate-rhel8",
                    "defaultStatus": "affected",
                    "cpes": [
                        "cpe:/a:redhat:openshift:4"
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://access.redhat.com/errata/RHSA-2026:57361",
                    "name": "RHSA-2026:57361",
                    "tags": [
                        "vendor-advisory",
                        "x_refsource_REDHAT"
                    ]
                },
                {
                    "url": "https://access.redhat.com/errata/RHSA-2026:60444",
                    "name": "RHSA-2026:60444",
                    "tags": [
                        "vendor-advisory",
                        "x_refsource_REDHAT"
                    ]
                },
                {
                    "url": "https://access.redhat.com/errata/RHSA-2026:60449",
                    "name": "RHSA-2026:60449",
                    "tags": [
                        "vendor-advisory",
                        "x_refsource_REDHAT"
                    ]
                },
                {
                    "url": "https://access.redhat.com/security/cve/CVE-2026-15809",
                    "tags": [
                        "vdb-entry",
                        "x_refsource_REDHAT"
                    ]
                },
                {
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2500846",
                    "name": "RHBZ#2500846",
                    "tags": [
                        "issue-tracking",
                        "x_refsource_REDHAT"
                    ]
                },
                {
                    "url": "https://github.com/cri-o/cri-o/pull/6450"
                },
                {
                    "url": "https://github.com/cri-o/cri-o/pull/6524"
                }
            ],
            "datePublic": "2026-07-15T10:18:17.941Z",
            "problemTypes": [
                {
                    "descriptions": [
                        {
                            "cweId": "CWE-134",
                            "description": "Use of Externally-Controlled Format String",
                            "lang": "en",
                            "type": "CWE"
                        }
                    ]
                }
            ],
            "x_redhatCweChain": "CWE-134: Use of Externally-Controlled Format String",
            "workarounds": [
                {
                    "lang": "en",
                    "value": "Restrict access to users who can create or modify container workloads through appropriate RBAC permissions, apply security controls such as Security Context Constraints (SCCs) to limit privilege escalation, and enforce policies to run containers with reduced privileges (for example, as non-root) to reduce the impact of potential exploitation. Enable SELinux on affected nodes and consider admission controls to prevent potentially unsafe workload configurations."
                }
            ],
            "timeline": [
                {
                    "lang": "en",
                    "time": "2026-07-15T09:58:08.982Z",
                    "value": "Reported to Red Hat."
                },
                {
                    "lang": "en",
                    "time": "2026-07-15T10:18:17.941Z",
                    "value": "Made public."
                }
            ],
            "credits": [
                {
                    "lang": "en",
                    "value": "Red Hat would like to thank Nebojša Jaćović (Independent Security Researcher) for reporting this issue."
                }
            ],
            "providerMetadata": {
                "orgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
                "shortName": "redhat",
                "dateUpdated": "2026-09-01T19:55:44.952Z"
            },
            "x_generator": {
                "engine": "cvelib 1.8.0"
            }
        },
        "adp": [
            {
                "problemTypes": [
                    {
                        "descriptions": [
                            {
                                "type": "CWE",
                                "cweId": "CWE-116",
                                "lang": "en",
                                "description": "CWE-116 Improper Encoding or Escaping of Output"
                            }
                        ]
                    }
                ],
                "metrics": [
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "timestamp": "2026-07-15T13:06:08.620102Z",
                                "id": "CVE-2026-15809",
                                "options": [
                                    {
                                        "Exploitation": "none"
                                    },
                                    {
                                        "Automatable": "no"
                                    },
                                    {
                                        "Technical Impact": "total"
                                    }
                                ],
                                "role": "CISA Coordinator",
                                "version": "2.0.3"
                            }
                        }
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2026-07-15T13:06:21.972Z"
                }
            }
        ]
    }
}