CVE-2022-0811

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
16/03/2022
Last modified:
28/03/2022

Description

A flaw was found in CRI-O in the way it set kernel options for a pod. This issue allows anyone with rights to deploy a pod on a Kubernetes cluster that uses the CRI-O runtime to achieve a container escape and arbitrary code execution as root on the cluster node, where the malicious pod was deployed.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:kubernetes:cri-o:*:*:*:*:*:*:*:* 1.19.0 (including) 1.19.6 (excluding)
cpe:2.3:a:kubernetes:cri-o:*:*:*:*:*:*:*:* 1.20.0 (including) 1.20.7 (excluding)
cpe:2.3:a:kubernetes:cri-o:*:*:*:*:*:*:*:* 1.21.0 (including) 1.21.6 (excluding)
cpe:2.3:a:kubernetes:cri-o:*:*:*:*:*:*:*:* 1.22.0 (including) 1.22.3 (excluding)
cpe:2.3:a:kubernetes:cri-o:*:*:*:*:*:*:*:* 1.23.0 (including) 1.23.2 (excluding)