REDHAT-BUG-2500823: High severity cri-o cri-o vulnerability
A flaw was discovered in CRI-O's checkpoint and restore capability. If a container is restored from a checkpoint archive, CRI-O does not adequately validate the restore metadata. A sufficiently privileged user could therefore cause unintended host filesystem activity during the restore process. This behavior is only reachable when checkpoint and restore has been explicitly enabled; it is not active in the default CRI-O/OpenShift configuration. Exploitation also depends on the attacker being able to initiate a restore operation using checkpoint data that they control or supply.