CVE-2022-0811: Code Injection
A flaw introduced in CRI-O version 1.19 which an attacker can use to bypass the safeguards and set arbitrary kernel parameters on the host. As a result, anyone with rights to deploy a pod on a Kubernetes cluster that uses the CRI-O runtime can abuse the “kernel.corepattern” kernel parameter to achieve container escape and arbitrary code execution as root on any node in the cluster.
Other sources
A flaw was found in CRI-O in the way it set kernel options for a pod. This issue allows anyone with rights to deploy a pod on a Kubernetes cluster that uses the CRI-O runtime to achieve a container escape and arbitrary code execution as root on the cluster node, where the malicious pod was deployed.
Affected Software
Remediation
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2022-0811?
CVE-2022-0811 is a vulnerability in CRI-O that allows a container escape and arbitrary code execution as root on a Kubernetes cluster.
What is the severity of CVE-2022-0811?
CVE-2022-0811 has a severity rating of 8.8 (Critical).
Which software is affected by CVE-2022-0811?
The affected software includes CRI-O versions up to 1.24.0, 1.23.2, 1.22.3, 1.21.6, and 1.20.7.
How can I fix CVE-2022-0811?
To fix CVE-2022-0811, update your CRI-O installation to version 1.24.0, 1.23.2, 1.22.3, 1.21.6, or 1.20.7.
Where can I find more information about CVE-2022-0811?
You can find more information about CVE-2022-0811 in the Red Hat Bugzilla and Red Hat Security Advisories.