Skip to content
COOEY

FAIL › dossier

linuxfoundation

VENDOR

· dossier confidence 0%

The Linux Foundation hosts foundational open-source projects but lacks direct security oversight, resulting in a track record of critical RCE and privilege escalation vulnerabilities across container runtimes, CI/CD pipelines, and kernel subsystems.

PROFILE
CategoryOpen-Source Software FoundationWhat they doThe Linux Foundation is a non-profit organization that hosts and supports open-source projects, including the Linux kernel, Kubernetes, and various container technologies.
SECURITY POSTURE

The Linux Foundation hosts critical open-source infrastructure but has no direct security control over the projects it supports; security posture is entirely dependent on the individual project maintainers and their patching cadences.

Notable failures
  • CVE-2026-50195 containerd RCE0day
  • CVE-2026-53492 containerd CDI trust bypass
  • CVE-2026-33211 Tekton Pipelines RCE
  • CVE-2026-44477 CloudNativePG vulnerability
  • CVE-2026-34045 Podman Desktop vulnerability
  • CVE-2026-33701 OpenTelemetry Java Instrumentation vulnerability
Patterns: Critical RCE vulnerabilities in container runtime and CI/CD tooling; Improper trust of external annotations (CDI); Use-after-free in kernel subsystems (iSCSI)
FAILURE HISTORY · 8
DATEEVENTSEVSUMMARY
2026-07-01 CVE-2026-50195 critical containerd is an open-source container runtime. Versions prior to 2.3.2, 2.2.5 and 2.1.9 contain a vulnerability in the CRI checkpoint import process where it fails to validate the image references specified within a checkpoint image's configuration. An attacker with permissions
2026-07-01 CVE-2026-53492 critical containerd is an open-source container runtime. In Versions prior to 2.3.2, 2.2.5 and 2.1.9, the CRI implementation improperly trusts Container Device Interface (CDI) annotations found within untrusted checkpoint image metadata during container restoration. When restoring a conta
2026-03-24 CVE-2026-33211 critical Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.1, 1.3.3, 1.6.1, 1.9.2, and 1.10.2, the Tekton Pipelines git resolver is vulnerable to path traversal via the `pathInRepo` parameter. A t
2026-05-28 CVE-2026-44477 critical CVE-2026-44477: CloudNativePG is a platform designed to manage PostgreSQL databases within Kuber
2026-04-07 CVE-2026-34045 high CVE-2026-34045: Podman Desktop is a graphical tool for developing on containers and Kubernetes.
2026-03-27 CVE-2026-33701 critical CVE-2026-33701: OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation a
2026-03-18 CVE-2026-28500 high CVE-2026-28500: Open Neural Network Exchange (ONNX) is an open standard for machine learning int
2026-03-07 CVE-2026-29186 high CVE-2026-29186: Backstage is an open framework for building developer portals. Prior to version
Open questions: Are these vulnerabilities attributed to the Linux Foundation's project management or the individual maintainers? · What is the Linux Foundation's vulnerability disclosure and patching SLA for its hosted projects?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-18 04:04:09.513733+00:00