Back to search
CVE-2022-0532
Published: Feb 9, 2022
Modified: Aug 2, 2024
PUBLISHED
Description
An incorrect sysctls validation vulnerability was found in CRI-O 1.18 and earlier. The sysctls from the list of "safe" sysctls specified for the cluster will be applied to the host if an attacker is able to create a pod with a hostIPC and hostNetwork kernel namespace.
| Vendor | Product | Versions |
|---|---|---|
n/a | cri-o | affected 1.18 |
Weaknesses (CWE)
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now