CVE Database
/

CVE-2022-0532

Back to search

CVE-2022-0532

Published: Feb 9, 2022

Modified: Aug 2, 2024

PUBLISHED

Description

An incorrect sysctls validation vulnerability was found in CRI-O 1.18 and earlier. The sysctls from the list of "safe" sysctls specified for the cluster will be applied to the host if an attacker is able to create a pod with a hostIPC and hostNetwork kernel namespace.

VendorProductVersions

n/a

cri-o

affected
1.18

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now