RATATOSKRATATOSK
Sign in

CRI-O

v1.35.7Kubernetes Core
Aug 24, 2026

ACTION 1

A security maintenance release fixes a vulnerability involving newline handling in the `HOME` environment variable. The fix addresses a bypass that could allow `/etc/passwd` injection.

Action needed (1)

  • securityhighCVE-2026-15809 newline handling in HOME

    Fixes CVE-2026-15809, which allowed /etc/passwd injection through newline characters in the HOME environment variable. The check now matches actual newline bytes instead of the literal string "\n".

Add CRI-O to your stack

A weekly email arrives when a release needs action. Like the security patches in this release.

Add to stack