Описание
A flaw was found in CRI-O in the way it set kernel options for a pod. This issue allows anyone with rights to deploy a pod on a Kubernetes cluster that uses the CRI-O runtime to achieve a container escape and arbitrary code execution as root on the cluster node, where the malicious pod was deployed.
Отчет
OpenShift Container Platform (OCP) starting from version 4.6 is affected by this vulnerability, older versions of OCP are not affected.
Меры по смягчению последствий
Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat OpenShift Container Platform 3.11 | cri-o | Not affected | ||
Red Hat OpenShift Container Platform 4.10 | cri-o | Fixed | RHSA-2022:0810 | 15.03.2022 |
Red Hat OpenShift Container Platform 4.6 | cri-o | Fixed | RHSA-2022:0866 | 23.03.2022 |
Red Hat OpenShift Container Platform 4.7 | cri-o | Fixed | RHSA-2022:0870 | 22.03.2022 |
Red Hat OpenShift Container Platform 4.8 | cri-o | Fixed | RHSA-2022:0871 | 22.03.2022 |
Red Hat OpenShift Container Platform 4.9 | cri-o | Fixed | RHSA-2022:0860 | 21.03.2022 |
Показывать по
Дополнительная информация
Статус:
EPSS
8.8 High
CVSS3
Связанные уязвимости
A flaw was found in CRI-O in the way it set kernel options for a pod. This issue allows anyone with rights to deploy a pod on a Kubernetes cluster that uses the CRI-O runtime to achieve a container escape and arbitrary code execution as root on the cluster node, where the malicious pod was deployed.
A flaw was found in CRI-O in the way it set kernel options for a pod. This issue allows anyone with rights to deploy a pod on a Kubernetes cluster that uses the CRI-O runtime to achieve a container escape and arbitrary code execution as root on the cluster node, where the malicious pod was deployed.
A flaw was found in CRI-O in the way it set kernel options for a pod. ...
EPSS
8.8 High
CVSS3