CVE-2022-0811

Name
CVE-2022-0811
Description
A flaw was found in CRI-O in the way it set kernel options for a pod. This issue allows anyone with rights to deploy a pod on a Kubernetes cluster that uses the CRI-O runtime to achieve a container escape and arbitrary code execution as root on the cluster node, where the malicious pod was deployed.
NVD Severity
high
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://bugzilla.redhat.com/show_bug.cgi?id=2059475
MISC https://github.com/cri-o/cri-o/security/advisories/GHSA-6x2m-w449-qwx7

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:kubernetes:cri-o:*:*:*:*:*:*:*:* cri-o >= 1.19.0 < 1.19.6
cpe:2.3:a:kubernetes:cri-o:*:*:*:*:*:*:*:* cri-o >= 1.20.0 < 1.20.7
cpe:2.3:a:kubernetes:cri-o:*:*:*:*:*:*:*:* cri-o >= 1.21.0 < 1.21.6
cpe:2.3:a:kubernetes:cri-o:*:*:*:*:*:*:*:* cri-o >= 1.22.0 < 1.22.3
cpe:2.3:a:kubernetes:cri-o:*:*:*:*:*:*:*:* cri-o >= 1.23.0 < 1.23.2

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
cri-o edge-community 1.23.2-r0 None fixed
cri-o 3.22-community 1.23.2-r0 None fixed
cri-o 3.21-community 1.23.2-r0 None fixed