CVE-2022-0811
Vulnerability Summary
Timeline
Description
A flaw was found in CRI-O in the way it set kernel options for a pod. This issue allows anyone with rights to deploy a pod on a Kubernetes cluster that uses the CRI-O runtime to achieve a container escape and arbitrary code execution as root on the cluster node, where the malicious pod was deployed.
CVSS Metrics
- v3.1•HIGH•Score: 8.8CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- v2.0•HIGH•Score: 9AV:N/AC:L/Au:S/C:C/I:C/A:C
EPSS Trends
Current EPSS score: 23.78%• Percentile: 96%
Techniques & Countermeasures
- CWE-94•Improper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Affected Systems
- github.com/cri-o•cri-o
≥ 1.19.0, < 1.19.6 | ≥ 1.20.0, < 1.20.7 | ≥ 1.21.0, < 1.21.6 | ≥ 1.22.0, < 1.22.3 | ≥ 1.23.0, < 1.23.2
- kubernetes•cri-o
≥ 1.19.0, < 1.19.6 | ≥ 1.20.0, < 1.20.7 | ≥ 1.21.0, < 1.21.6 | ≥ 1.22.0, < 1.22.3 | ≥ 1.23.0, < 1.23.2
References (7)
- https://bugzilla.redhat.com/show_bug.cgi?id=2059475
- https://github.com/cri-o/cri-o/security/advisories/GHSA-6x2m-w449-qwx7
- https://nvd.nist.gov/vuln/detail/CVE-2022-0811
- https://access.redhat.com/security/cve/CVE-2022-0811
- https://bugs.gentoo.org/835336
- https://github.com/cri-o/cri-o
- https://www.crowdstrike.com/blog/cr8escape-zero-day-vulnerability-discovered-in-cri-o-container-engine-cve-2022-0811