CVE-2022-0811
16.03.2022, 15:15
A flaw was found in CRI-O in the way it set kernel options for a pod. This issue allows anyone with rights to deploy a pod on a Kubernetes cluster that uses the CRI-O runtime to achieve a container escape and arbitrary code execution as root on the cluster node, where the malicious pod was deployed.
Vendor | Product | Version |
---|---|---|
kubernetes | cri-o | 1.19.0 ≤ 𝑥 < 1.19.6 |
kubernetes | cri-o | 1.20.0 ≤ 𝑥 < 1.20.7 |
kubernetes | cri-o | 1.21.0 ≤ 𝑥 < 1.21.6 |
kubernetes | cri-o | 1.22.0 ≤ 𝑥 < 1.22.3 |
kubernetes | cri-o | 1.23.0 ≤ 𝑥 < 1.23.2 |
𝑥
= Vulnerable software versions