A container breakout was reported in cri-o, where a malicious container image can trick cri-o into creating a symlink on the host. The reproducer that was provided created the following symlink: /root/mtab -> /proc/mounts.
Created cri-o tracking bugs for this issue: Affects: fedora-all [bug 2290762] Created cri-o:1.21/cri-o tracking bugs for this issue: Affects: epel-all [bug 2290761] Created cri-o:1.22/cri-o tracking bugs for this issue: Affects: fedora-all [bug 2290763] Created cri-o:1.23/cri-o tracking bugs for this issue: Affects: fedora-all [bug 2290764] Created cri-o:1.24/cri-o tracking bugs for this issue: Affects: fedora-all [bug 2290765] Created cri-o:1.25/cri-o tracking bugs for this issue: Affects: fedora-all [bug 2290766] Created cri-o:1.26/cri-o tracking bugs for this issue: Affects: fedora-all [bug 2290767] Created cri-o:1.27/cri-o tracking bugs for this issue: Affects: fedora-all [bug 2290768]
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.15 Via RHSA-2024:3676 https://access.redhat.com/errata/RHSA-2024:3676
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.14 Via RHSA-2024:3700 https://access.redhat.com/errata/RHSA-2024:3700
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.12 Via RHSA-2024:4008 https://access.redhat.com/errata/RHSA-2024:4008
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.13 Via RHSA-2024:4486 https://access.redhat.com/errata/RHSA-2024:4486
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.17 Via RHSA-2024:10818 https://access.redhat.com/errata/RHSA-2024:10818