Описание
An incorrect sysctls validation vulnerability was found in CRI-O 1.18 and earlier. The sysctls from the list of "safe" sysctls specified for the cluster will be applied to the host if an attacker is able to create a pod with a hostIPC and hostNetwork kernel namespace.
An incorrect sysctls validation vulnerability was found in CRI-O. The sysctls from the list of "safe" sysctls specified for the cluster [0] will be applied to the host if an attacker can create a pod with a hostIPC and hostNetwork kernel namespace.
Отчет
Red Hat OpenShift Container Platform (OCP) uses a vulnerable version of CRI-O, but a successful exploit requires access to at least hostnetwork SCC (Security Context Constraints) or privileged SCC. The default restricted SCC blocks this vulnerability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat OpenShift Container Platform 3.11 | cri-o | Out of support scope | ||
| Red Hat OpenShift Container Platform 4.10 | cri-o | Fixed | RHSA-2022:0055 | 10.03.2022 |
| Red Hat OpenShift Container Platform 4.6 | cri-o | Fixed | RHSA-2022:0866 | 23.03.2022 |
| Red Hat OpenShift Container Platform 4.7 | cri-o | Fixed | RHSA-2022:0870 | 22.03.2022 |
| Red Hat OpenShift Container Platform 4.8 | cri-o | Fixed | RHBA-2022:0793 | 16.03.2022 |
| Red Hat OpenShift Container Platform 4.9 | cri-o | Fixed | RHBA-2022:0794 | 16.03.2022 |
Показывать по
Дополнительная информация
Статус:
EPSS
4.2 Medium
CVSS3
Связанные уязвимости
An incorrect sysctls validation vulnerability was found in CRI-O 1.18 and earlier. The sysctls from the list of "safe" sysctls specified for the cluster will be applied to the host if an attacker is able to create a pod with a hostIPC and hostNetwork kernel namespace.
An incorrect sysctls validation vulnerability was found in CRI-O 1.18 and earlier. The sysctls from the list of "safe" sysctls specified for the cluster will be applied to the host if an attacker is able to create a pod with a hostIPC and hostNetwork kernel namespace.
An incorrect sysctls validation vulnerability was found in CRI-O 1.18 ...
Incorrect Permission Assignment for Critical Resource in CRI-O
EPSS
4.2 Medium
CVSS3