CVE-2022-2995: High severity Kubernetes CRI-O vulnerability
Incorrect handling of the supplementary groups in the CRI-O container engine might lead to sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to set access permissions and is able to execute a binary code in that container.
https://github.com/cri-o/cri-o/pull/6159
Affected Software
Remediation
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2022-2995?
CVE-2022-2995 is a vulnerability in the CRI-O container engine that can lead to sensitive information disclosure or possible data modification.
What is the severity of CVE-2022-2995?
The severity of CVE-2022-2995 is high with a CVSS score of 7.1.
How does CVE-2022-2995 affect CRI-O?
CVE-2022-2995 affects CRI-O by incorrectly handling the supplementary groups, which can result in sensitive information disclosure or possible data modification.
How can I mitigate CVE-2022-2995?
To mitigate CVE-2022-2995, update CRI-O to version 1.25.0 or apply the recommended patches provided by Red Hat.
Where can I find more information about CVE-2022-2995?
You can find more information about CVE-2022-2995 on the NIST NVD website, the GitHub pull request, and the Bentham's Gaze article.