REDHAT-BUG-2506872: Medium severity cri-o cri-o vulnerability
A flaw was found in CRI-O, the container runtime. Under a specific internal condition, CRI-O skips checking whether a container image's environment variable settings are properly formatted before using them. If an image contains a malformed environment variable, CRI-O crashes while trying to process it.
Affected Software
Event History
Frequently Asked Questions
What conditions are required to trigger the crash?
CRI-O must process a container image containing a malformed environment-variable setting, and the specific internal condition that causes CRI-O to skip validation must occur.
What is the likely operational impact?
CRI-O crashes while processing the malformed environment variable. Systems using CRI-O to run or start affected images may experience container runtime disruption.
How can I assess whether I may be exposed?
Identify workloads that use CRI-O and review container images they process for malformed environment-variable settings. The available information does not specify the affected versions or a detection method for the internal condition.