A flaw introduced in CRI-O version 1.19 which an attacker can use to bypass the safeguards and set arbitrary kernel parameters on the host. As a result, anyone with rights to deploy a pod on a Kubernetes cluster that uses the CRI-O runtime can abuse the “kernel.core_pattern” kernel parameter to achieve container escape and arbitrary code execution as root on any node in the cluster.
Created cri-o tracking bugs for this issue: Affects: fedora-all [bug 2064293]
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.10 Via RHSA-2022:0810 https://access.redhat.com/errata/RHSA-2022:0810
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2022-0811
Created cri-o:1.19/cri-o tracking bugs for this issue: Affects: fedora-all [bug 2066126]
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.9 Via RHSA-2022:0860 https://access.redhat.com/errata/RHSA-2022:0860
Created cri-o:1.17/cri-o tracking bugs for this issue: Affects: fedora-all [bug 2066468] Created cri-o:1.18/cri-o tracking bugs for this issue: Affects: fedora-all [bug 2066469] Created cri-o:1.20/cri-o tracking bugs for this issue: Affects: fedora-all [bug 2066470] Created cri-o:1.21/cri-o tracking bugs for this issue: Affects: fedora-all [bug 2066471] Created cri-o:1.22/cri-o tracking bugs for this issue: Affects: fedora-all [bug 2066472] Created cri-o:nightly/cri-o tracking bugs for this issue: Affects: fedora-all [bug 2066473]
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.7 Via RHSA-2022:0870 https://access.redhat.com/errata/RHSA-2022:0870
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.8 Via RHSA-2022:0871 https://access.redhat.com/errata/RHSA-2022:0871
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.6 Via RHSA-2022:0866 https://access.redhat.com/errata/RHSA-2022:0866