← Back to CVE List
Vulnerability Intelligence Report
Github.com/cri-o/cri-o: fix bypass for cve-2022-4318 — /etc/passwd injection via home env

CVE-2026-15809

A flaw was found in CRI-O. The fix for a previous vulnerability (CVE-2022-4318) was incorrect, allowing it to be bypassed. An attacker capable of setting environment variables on a container can inject a newline character into the HOME environment variable. This issue allows the addition of arbitrary lines into /etc/passwd by use of a specially crafted environment variable.

No Active Exploit Signals
CVSS Base Score
7.8
HIGH
Exploitability:1.9
Impact Score:5.9
EPSS Probability:0.18%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-134 ↗Use of Externally-Controlled Format String

Affected Products & Versions

Vendor Product Affected Versions
Red Hat Red Hat OpenShift Container Platform 4.12 0:1.25.5-36.rhaos4.12.git2e7f657.el8 < * (unaffected)
Red Hat Red Hat OpenShift Container Platform 4.13 0:1.26.5-32.rhaos4.13.git1088e36.el8 < * (unaffected)
Red Hat Red Hat OpenShift Container Platform 4.14 0:1.27.8-22.rhaos4.14.git0633bf1.el8 < * (unaffected)
Red Hat Red Hat OpenShift Container Platform 4.15 0:1.28.11-17.rhaos4.15.git48e6ddb.el8 < * (unaffected)
Red Hat Red Hat OpenShift Container Platform 4.16 0:1.29.13-14.rhaos4.16.git84cfdc6.el8 < * (unaffected)
Red Hat Red Hat OpenShift Container Platform 4.18 0:1.31.13-14.rhaos4.18.gitf2de9ac.el8 < * (unaffected)
Red Hat Red Hat OpenShift Container Platform 4.19 0:1.32.13-11.rhaos4.19.git089e95c.el9 < * (unaffected)
Red Hat Red Hat OpenShift Container Platform 4.20 0:1.33.13-5.rhaos4.20.git7ebc848.el9 < * (unaffected)
Red Hat Red Hat OpenShift Container Platform 4.21 0:1.34.11-4.rhaos4.21.git358c4b4.el9 < * (unaffected)
Red Hat Red Hat OpenShift Container Platform 4.22 0:1.35.6-5.rhaos4.22.git41f610b.el9 < * (unaffected)
Red Hat Confidential Compute Attestation all
Red Hat Red Hat OpenShift Container Platform 4 all
Red Hat Red Hat OpenShift Container Platform 4 all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.176%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityRed Hat, Inc. · Vendor · USA
Reserved2026-07-15T09:57:48
Published2026-07-15T12:32:42
Patch Date2026-07-15
Last Updated2026-09-25T03:28:19

LINK COPIED TO CLIPBOARD