Fedora Account System
Red Hat Associate
Red Hat Customer
The fix for CVE-2022-4318 in CRI-O is incorrect and has been bypassable since it was introduced on December 14, 2022. The check in server/container_create.go uses a Go raw string literal (`\n`) instead of an interpreted string literal ("\n"), causing it to search for the literal two-character sequence backslash-n (0x5c 0x6e) rather than an actual newline character (0x0a). An attacker who can set environment variables on a container (via the CRI CreateContainer request) can supply a real newline character in the HOME environment variable, bypassing the check entirely. The unsanitized value is then passed to utils.GeneratePasswd, which uses fmt.Sprintf to construct the container's /etc/passwd content, allowing arbitrary line injection.
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.22 Via RHSA-2026:57361 https://access.redhat.com/errata/RHSA-2026:57361
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.20 Via RHSA-2026:60444 https://access.redhat.com/errata/RHSA-2026:60444
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.21 Via RHSA-2026:60449 https://access.redhat.com/errata/RHSA-2026:60449
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.19 Via RHSA-2026:60452 https://access.redhat.com/errata/RHSA-2026:60452
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.16 Via RHSA-2026:62548 https://access.redhat.com/errata/RHSA-2026:62548
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.13 Via RHSA-2026:65838 https://access.redhat.com/errata/RHSA-2026:65838
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.12 Via RHSA-2026:65906 https://access.redhat.com/errata/RHSA-2026:65906
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.18 Via RHSA-2026:66385 https://access.redhat.com/errata/RHSA-2026:66385
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.14 Via RHSA-2026:67836 https://access.redhat.com/errata/RHSA-2026:67836
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.15 Via RHSA-2026:67856 https://access.redhat.com/errata/RHSA-2026:67856
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.17 Via RHSA-2026:70585 https://access.redhat.com/errata/RHSA-2026:70585