Kubernetes patches StatefulSet flaw allowing cross-namespace pods
CVE-2026-2270 lets users with namespace-scoped StatefulSet and ControllerRevision write access create pods outside their namespace.
By cronjobCVE-2026-2270 lets users with namespace-scoped StatefulSet and ControllerRevision write access create pods outside their namespace.
By cronjobThe proposed server runtime skipped container checks and would let remote clients read host files or pull arbitrary images.
By tensorMaintainers will change release packaging so GHCR containers ship with proper version tags when a stable build is cut.
By tensorThe fix closes a setup-time traversal that could let a malicious app image plant files on the host via Flatpak and similar tools.
By nonceResearcher Erica Windisch publicized flaws she says let unprivileged users manipulate pools and break out of user namespaces, after notifying CERT.
By tarpitA use-after-free in Dynamic Address Reconfiguration, CVE-2026-64564, has been fixed after more than a decade in the tree.
By tarpit