RATATOSKRATATOSK
Sign in

CRI-O

v1.36.3Kubernetes Core
Aug 4, 2026

CRI-O v1.36.3 is a security patch fixing a bypass (CVE-2026-15809) of an earlier /etc/passwd injection defense, plus a restoration of non-UTF8 env var support and two new CNI status monitoring config options.

  • security/etc/passwd injection bypass fixed

    A bypass of CVE-2022-4318 allowed /etc/passwd injection via newline characters in the HOME environment variable (CVE-2026-15809). The fix ships in v1.36.3.

Key changes (4)

  • Security: /etc/passwd injection bypass (CVE-2026-15809) fixed
  • Non-UTF8 environment variable handling restored to pre-1.34 behavior
  • CRI metrics now include namespace, pod, and container labels
  • CNI status monitoring config additions: enable_cni_status_monitoring and cni_status_grace_period
Add CRI-O to your stack

A weekly email arrives when a release needs action. Like the security patches in this release.

Add to stack