FAIL › dossier
linuxfoundation
VENDOR· dossier confidence 0%
The Linux Foundation hosts foundational open-source projects but lacks direct security oversight, resulting in a track record of critical RCE and privilege escalation vulnerabilities across container runtimes, CI/CD pipelines, and kernel subsystems.
PROFILE
CategoryOpen-Source Software FoundationWhat they doThe Linux Foundation is a non-profit organization that hosts and supports open-source projects, including the Linux kernel, Kubernetes, and various container technologies.
SECURITY POSTURE
The Linux Foundation hosts critical open-source infrastructure but has no direct security control over the projects it supports; security posture is entirely dependent on the individual project maintainers and their patching cadences.
Notable failures
- CVE-2026-50195 containerd RCE0day
- CVE-2026-53492 containerd CDI trust bypass
- CVE-2026-33211 Tekton Pipelines RCE
- CVE-2026-44477 CloudNativePG vulnerability
- CVE-2026-34045 Podman Desktop vulnerability
- CVE-2026-33701 OpenTelemetry Java Instrumentation vulnerability
Patterns: Critical RCE vulnerabilities in container runtime and CI/CD tooling; Improper trust of external annotations (CDI); Use-after-free in kernel subsystems (iSCSI)
FAILURE HISTORY · 8
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2026-07-01 | CVE-2026-50195 | critical | containerd is an open-source container runtime. Versions prior to 2.3.2, 2.2.5 and 2.1.9 contain a vulnerability in the CRI checkpoint import process where it fails to validate the image references specified within a checkpoint image's configuration. An attacker with permissions |
| 2026-07-01 | CVE-2026-53492 | critical | containerd is an open-source container runtime. In Versions prior to 2.3.2, 2.2.5 and 2.1.9, the CRI implementation improperly trusts Container Device Interface (CDI) annotations found within untrusted checkpoint image metadata during container restoration. When restoring a conta |
| 2026-03-24 | CVE-2026-33211 | critical | Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.1, 1.3.3, 1.6.1, 1.9.2, and 1.10.2, the Tekton Pipelines git resolver is vulnerable to path traversal via the `pathInRepo` parameter. A t |
| 2026-05-28 | CVE-2026-44477 | critical | CVE-2026-44477: CloudNativePG is a platform designed to manage PostgreSQL databases within Kuber |
| 2026-04-07 | CVE-2026-34045 | high | CVE-2026-34045: Podman Desktop is a graphical tool for developing on containers and Kubernetes. |
| 2026-03-27 | CVE-2026-33701 | critical | CVE-2026-33701: OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation a |
| 2026-03-18 | CVE-2026-28500 | high | CVE-2026-28500: Open Neural Network Exchange (ONNX) is an open standard for machine learning int |
| 2026-03-07 | CVE-2026-29186 | high | CVE-2026-29186: Backstage is an open framework for building developer portals. Prior to version |
DOSSIER SOURCES
- Linux CVEs and Security Vulnerabilities - OpenCVE · app.opencve.io
- Linux Kernel CVEs and Security Vulnerabilities - OpenCVE · app.opencve.io
- Vulnerability DB | Snyk · security.snyk.io
Open questions: Are these vulnerabilities attributed to the Linux Foundation's project management or the individual maintainers? · What is the Linux Foundation's vulnerability disclosure and patching SLA for its hosted projects?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-18 04:04:09.513733+00:00