CVE-2022-0532

An incorrect sysctls validation vulnerability was found in CRI-O 1.18 and earlier. The sysctls from the list of "safe" sysctls specified for the cluster will be applied to the host if an attacker is able to create a pod with a hostIPC and hostNetwork kernel namespace.
Configurations

Configuration 1

cpe:2.3:a:kubernetes:cri-o:*:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*

Information

Published : 2022-02-09 11:15

Updated : 2022-02-22 08:56


NVD link : CVE-2022-0532

Mitre link : CVE-2022-0532

Products Affected
No products.
CWE