CVE-2022-0811
This issue allows anyone with rights to deploy a pod on a Kubernetes cluster that uses the CRI-O runtime to achieve a container escape and arbitrary code execution as root on the cluster node, where the malicious pod was deployed.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 19.0%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
A flaw was found in CRI-O in the way it set kernel options for a pod. This issue allows anyone with rights to deploy a pod on a Kubernetes cluster that uses the CRI-O runtime to achieve a container escape and arbitrary code execution as root on the cluster node, where the malicious pod was deployed.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 19.05% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- kubernetes/cri-o
- Source
- secalert@redhat.com
References
- https://bugzilla.redhat.com/show_bug.cgi?id=2059475Issue Tracking, Third Party Advisory
- https://github.com/cri-o/cri-o/security/advisories/GHSA-6x2m-w449-qwx7Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2059475Issue Tracking, Third Party Advisory
- https://github.com/cri-o/cri-o/security/advisories/GHSA-6x2m-w449-qwx7Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.