CVE-2023-6476: Cri-o: pods are able to break out of resource confinement on cgroupv2

Published Dec 11, 2023
·
Updated

Impact What kind of vulnerability is it? Who is impacted? All versions of CRI-O running on cgroupv2 nodes. Unchecked access to an experimental annotation allows a container to be unconfined. Back in 2021, support was added to support an experimental annotation that allows a user to request special resources in cgroupv2. It was supposed to be gated by an experimental annotation: io.kubernetes.cri-o.UnifiedCgroup, which was supposed to be filtered from the list of allowed annotations . However, there is a bug in this code which allows any user to specify this annotation, regardless of whether it's enabled on the node. The consequences of this are a pod can specify any amount of memory/cpu and get it, circumventing the kubernetes scheduler, and potentially be able to DOS a node. Patches Has the problem been patched? What versions should users upgrade to? 1.29.1, 1.28.3, 1.27.3

Workarounds Is there a way for users to fix or remediate the vulnerability without upgrading? use cgroupv1

References Are there any links users can visit to find out more?

Other sources

A flaw was found in CRI-O that involves an experimental annotation leading to a container being unconfined. This may allow a pod to specify and get any amount of memory/cpu, circumventing the kubernetes scheduler and potentially resulting in a denial of service in the node.

NVD

A vulnerability in CRI-O that involves an experimental annotation leading to a container being unconfined. Back in 2021, Giuseppe put up a PR to add support for an experimental annotation that allows a user to request special resources in cgroupv2. It was supposed to be gated by an experimental annotation: io.kubernetes.cri-o.UnifiedCgroup, which was supposed to be filtered from the list of allowed annotations . However, there is a bug in this code which allows any user to specify this annotation, regardless of whether it's enabled on the node.

The consequences of this are a pod can specify any amount of memory/cpu and get it, circumventing the kubernetes scheduler, and potentially be able to DOS a node.

Red Hat

Cri-o: pods are able to break out of resource confinement on cgroupv2

Microsoft

Affected Software

11 affected componentsFixes available
go/github.com/cri-o/cri-o<1.27.3
1.27.3
go/github.com/cri-o/cri-o>=1.28.0<1.28.3
1.28.3
go/github.com/cri-o/cri-o=1.29.0
1.29.1
redhat/cri-o<1.29.1
1.29.1
redhat/cri-o<1.27.3
1.27.3
redhat OpenShift Container Platform=3.11
All of the following
Any of the following
redhat OpenShift Container Platform=4.13
redhat OpenShift Container Platform=4.14
Any of the following
redhat Enterprise Linux=8.0
redhat Enterprise Linux=9.0
Microsoft cbl2 cri-o 1.22.3-10<1.22.3-10
1.22.3-10

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade go/github.com/cri-o/cri-o to a version that resolves this vulnerability.

    Fixed in 1.27.3
  2. Upgrade

    Upgrade go/github.com/cri-o/cri-o to a version that resolves this vulnerability.

    Fixed in 1.28.3
  3. Upgrade

    Upgrade go/github.com/cri-o/cri-o to a version that resolves this vulnerability.

    Fixed in 1.29.1
  4. Upgrade

    Upgrade redhat/cri-o to a version that resolves this vulnerability.

    Fixed in 1.29.1
  5. Upgrade

    Upgrade redhat/cri-o to a version that resolves this vulnerability.

    Fixed in 1.28.3
  6. Upgrade

    Upgrade redhat/cri-o to a version that resolves this vulnerability.

    Fixed in 1.27.3
  7. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 1.22.3-10
  8. Upgrade

    Upgrade cri-o to a version that resolves this vulnerability.

    Fixed in 1.29.1
  9. Upgrade

    Upgrade cri-o to a version that resolves this vulnerability.

    Fixed in 1.28.3
  10. Upgrade

    Upgrade cri-o to a version that resolves this vulnerability.

    Fixed in 1.27.3
  11. Compensating control

    Use cgroupv1 (the issue affects all versions of CRI-O running on cgroupv2 nodes).

Event History

Jan 9, 2024
CVE Published
via MITRE·09:32 PM
Data Sourced
via MITRE·09:32 PM
DescriptionSeverityWeakness
Jan 10, 2024
Advisory Published
via GitHub·03:27 PM
Sep 4, 2025
Data Sourced
via Microsoft·04:08 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·04:08 AM
Affected Software
Updated
via Microsoft·04:08 AM
Affected Software
Updated
via Microsoft·04:08 AM
DescriptionSeverity

Frequently Asked Questions

1

What is the severity of CVE-2023-6476?

The severity of CVE-2023-6476 is classified as critical due to its potential impact on system security.

2

How do I fix CVE-2023-6476?

To fix CVE-2023-6476, upgrade to CRI-O version 1.27.3, 1.28.3, or 1.29.1.

3

Who is impacted by CVE-2023-6476?

CVE-2023-6476 impacts all versions of CRI-O running on cgroupv2 nodes.

4

What happens if I don’t address CVE-2023-6476?

If CVE-2023-6476 is not addressed, containers may be unconfined, leading to potential security breaches.

5

Is CVE-2023-6476 present in Red Hat products?

Yes, CVE-2023-6476 is present in specific versions of Red Hat OpenShift Container Platform and Red Hat Enterprise Linux.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203