Continue reading the full briefing.
Operational focus: Keep audit logs outside the workload account and verify they cover the affected control plane.
Open the original NIST National Vulnerability Database record
USN-8617-1: Linux kernel (KVM) vulnerabilities
It was discovered that a logic flaw existed in the XFRM ESP-in-TCP subsystem in the Linux kernel when handling socket buffer fragments. This flaw is known as Fragnesia. A local attacker could use this to escalate privileges, or possibly escape a container. (CVE-2026-43503) Several security issues were discovered in the Linux kernel. An attacker could possibly use these…
Why it matters: Ubuntu Security Notices may be embedded across servers, containers, appliances, and administration hosts. Package installation alone does not prove that the corrected code is running.
What to verify: Compare distribution package versions, identify the loaded kernel or library, plan required service restarts or reboots, and validate workload health after the change.
Operational focus: Confirm whether the provider has remediated the platform or whether tenant configuration remains exposed.
USN-8616-1: Linux kernel (IBM) vulnerabilities
It was discovered that the Linux kernel did not properly handle shared page fragments during socket buffer operations, collectively known as Dirty Frag. A logic flaw existed in the XFRM ESP-in-TCP subsystem and in the RxRPC networking subsystem when processing paged fragments. A local attacker could use this to escalate privileges, or possibly escape a container. (CVE-2026-43284, CVE-2026-43500)…
Why it matters: Ubuntu Security Notices may be embedded across servers, containers, appliances, and administration hosts. Package installation alone does not prove that the corrected code is running.
What to verify: Compare distribution package versions, identify the loaded kernel or library, plan required service restarts or reboots, and validate workload health after the change.
Operational focus: Review public endpoints, privileged identities, service accounts, and cross-account trust.
CVE-2026-55389: datamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal), bypassing `–no-allow-remote-refs`
### Summary `datamodel-code-generator` resolves JSON-Schema `$ref` targets that point at the local filesystem without restricting them to the input/base directory and without honoring the remote-reference security control. In the default configuration, an attacker who controls an input schema (a "paste your OpenAPI/JSON-Schema" service, a CI job that generates models from a submitted spec, or any multi-tenant codegen platform)…
Why it matters: GitHub Advisory Database datamodel-code-generator participates in the path from source code to production. A weakness can inherit runner permissions, build secrets, trusted artifacts, or deployment access.
What to verify: Trace untrusted input through pull requests and jobs, review token scope, isolate runners, pin trusted dependencies, and rebuild affected artifacts after remediation.
Operational focus: Keep audit logs outside the workload account and verify they cover the affected control plane.
CVE-2026-13463: IBM Cloud Pak System 2.3.5.0 could allow a local attacker to obtain…
IBM Cloud Pak System 2.3.5.0 could allow a local attacker to obtain sensitive information due to the insertion of credentials into log files.
Why it matters: CVE-2026-13463 needs an account, region, identity path, exposure state, and provider-versus-tenant ownership decision.
What to verify: Confirm the affected version and reachable component, preserve useful telemetry, apply the publisher guidance, and record the evidence used to close the item.
Operational focus: Confirm whether the provider has remediated the platform or whether tenant configuration remains exposed.
Open the original NIST National Vulnerability Database record
CVE-2026-18107: A flaw was found in CRIU's handling of restartable sequences (rseq) during…
A flaw was found in CRIU's handling of restartable sequences (rseq) during checkpoint/restore. A malicious process inside a container can register an rseq critical section that hijacks CRIU's parasite code injection during checkpoint, allowing it to spoof the process credentials saved in the checkpoint image. On restore, the container process gains elevated capabilities and zeroed UIDs/GIDs. The practical…
Why it matters: CVE-2026-18107 may be embedded across servers, containers, appliances, and administration hosts. Package installation alone does not prove that the corrected code is running.
What to verify: Compare distribution package versions, identify the loaded kernel or library, plan required service restarts or reboots, and validate workload health after the change.
Operational focus: Review public endpoints, privileged identities, service accounts, and cross-account trust.
Open the original NIST National Vulnerability Database record
Cloud response plan
Separate provider-side remediation from tenant-owned configuration. Check identities, public endpoints, workload images, service accounts, regions, and audit coverage before closing the issue.
- Map provider and package advisories to accounts, projects, regions, clusters, and managed services in use.
- Review public storage, load balancers, admin ports, and broad network rules.
- Remove stale keys, broad roles, unused service accounts, and persistent administrative access.
- Patch worker nodes, container images, agents, and self-managed control-plane components.
- Confirm centralized audit logging and alerting after every remediation.
Tenant checks
Verify the affected account and region, the identity path, public reachability, provider responsibility, and audit evidence.
- Confirm whether the provider has remediated the platform or whether tenant configuration remains exposed.
- Review public endpoints, privileged identities, service accounts, and cross-account trust.
- Keep audit logs outside the workload account and verify they cover the affected control plane.
Cloud team takeaway
Close cloud findings only after both the provider status and tenant configuration are understood, with centralized logs showing the repaired control is working.
References used in this briefing
- GitHub Advisory Database: CVE-2026-50570: Fission: Incomplete capability denylist in Environment/Function PodSpec validation allows tenant-added CAP_SYS_TIME and cross-tenant node wall-clock corruption
- GitHub Advisory Database: CVE-2026-50569: Fission: HTTPTrigger admission omits RelativeURL / Prefix validation; kubectl apply bypasses CLI checks
- NIST National Vulnerability Database: CVE-2026-57510: SuperPlane before 0.27.0 contains a broken object-level authorization vulnerability in the CanvasService…
- Ubuntu Security Notices: USN-8617-1: Linux kernel (KVM) vulnerabilities
- Ubuntu Security Notices: USN-8616-1: Linux kernel (IBM) vulnerabilities
- GitHub Advisory Database: CVE-2026-55389: datamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal), bypassing `–no-allow-remote-refs`
- NIST National Vulnerability Database: CVE-2026-13463: IBM Cloud Pak System 2.3.5.0 could allow a local attacker to obtain…
- NIST National Vulnerability Database: CVE-2026-18107: A flaw was found in CRIU's handling of restartable sequences (rseq) during…
Need to add context to this briefing?
Send corrections, security tips, source updates, or collaboration notes through the contact page so the editorial team can review them properly.


