First published: Wed Oct 12 2022(Updated: )
The following cri-o packages as released for Red Hat OpenShift Container Platform 4.9.48, 4.10.31 and 4.11.6 included an incorrect version of cri-o that was missing the fix for CVE-2022-27652: - cri-o-1.22.5-10.rhaos4.9.gitd14fede.el8 via RHBA-2022:6316 (<a href="https://access.redhat.com/errata/RHBA-2022:6316">https://access.redhat.com/errata/RHBA-2022:6316</a>) - cri-o-1.23.3-16.rhaos4.10.gitd7c9b35.el8 via RHBA-2022:6257 (<a href="https://access.redhat.com/errata/RHBA-2022:6257">https://access.redhat.com/errata/RHBA-2022:6257</a>) - cri-o-1.24.2-7.rhaos4.11.gitca400e0.el8 via RHBA-2022:6658 (<a href="https://access.redhat.com/errata/RHBA-2022:6658">https://access.redhat.com/errata/RHBA-2022:6658</a>) The regressed <a href="https://access.redhat.com/security/cve/CVE-2022-27652">CVE-2022-27652</a> was previously corrected in Red Hat OpenShift Container Platform 4.9.41 and 4.10.12 via RHBA-2022:5433 and RHSA-2022:1600, respectively. <a href="https://access.redhat.com/security/cve/CVE-2022-3466">CVE-2022-3466</a> was assigned to this security regression and it is specific to the cri-o packages produced by Red Hat. The original issue could allow an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs. For more details about the original issue, see: <a href="https://access.redhat.com/security/cve/CVE-2022-27652">https://access.redhat.com/security/cve/CVE-2022-27652</a> <a href="https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2022-27652">https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2022-27652</a>
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/cri-o | <0:1.25.1-5.rhaos4.12.git6005903.el8 | 0:1.25.1-5.rhaos4.12.git6005903.el8 |
Kubernetes CRI-O | ||
Redhat Openshift Container Platform | =3.11 | |
Redhat Openshift Container Platform | =4.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-3466 is a vulnerability in the cri-o component of Red Hat OpenShift Container Platform.
CVE-2022-3466 has a severity rating of medium with a CVSS score of 5.3.
Red Hat OpenShift Container Platform versions 4.9.48, 4.10.31, and 4.11.6 are affected.
The cri-o component in Red Hat OpenShift Container Platform is affected.
To fix the CVE-2022-3466 vulnerability, update cri-o to version 1.25.1-5.rhaos4.12.git6005903.el8 or later.