Cri-o: pods are able to break out of resource confinement on cgroupv2
Published Jan 9, 2024
7.5
HIGHCVSS 3.1
EPSS 0.86%
Description
A flaw was found in CRI-O that involves an experimental annotation leading to a container being unconfined. This may allow a pod to specify and get any amount of memory/cpu, circumventing the kubernetes scheduler and potentially resulting in a denial of service in the node.
Affected products
No data.
Configuration 1
- 3.11
Configuration 2
- 4.13
- 4.14
Running on/with
- 8.0
- 9.0
No data.
Red Hat OpenShift Container Platform 4.13
cri-o-0:1.26.4-6.1.rhaos4.13.git9eb9cf3.el8
Fixed · RHSA-2024:0195
Red Hat OpenShift Container Platform 4.14
cri-o-0:1.27.2-7.rhaos4.14.git1cc7a64.el8
Fixed · RHSA-2024:0207
Red Hat OpenShift Container Platform 3.11
cri-o
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift Container Platform 4.13 | cri-o-0:1.26.4-6.1.rhaos4.13.git9eb9cf3.el8 | Fixed | RHSA-2024:0195 |
| Red Hat OpenShift Container Platform 4.14 | cri-o-0:1.27.2-7.rhaos4.14.git1cc7a64.el8 | Fixed | RHSA-2024:0207 |
| Red Hat OpenShift Container Platform 3.11 | cri-o | Out of support scope | n/a |
github.com/cri-o/cri-o
Go
Introduced 1.29.0 Fixed 1.29.1github.com/cri-o/cri-o
Go
Introduced 1.28.0 Fixed 1.28.3github.com/cri-o/cri-o
Go
Introduced 0 Fixed 1.27.3
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/cri-o/cri-o | 1.29.0 | 1.29.1 |
| Go | github.com/cri-o/cri-o | 1.28.0 | 1.28.3 |
| Go | github.com/cri-o/cri-o | 0 | 1.27.3 |
Remediation
Red Hat statement
There are two main factors reduce the severity of this vulnerability to Moderate: * A potential attacker must already have valid credentials * The OpenShift environment must already be configured to use an experimental feature
References (12)
- https://access.redhat.com/errata/RHSA-2024:0195 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2024:0207 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/security/cve/CVE-2023-6476 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2253994 issue-trackingx_refsource_REDHATIssue TrackingVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-0390 Advisory
- https://github.com/advisories/GHSA-p4rx-7wvg-fwrc Advisory
- https://github.com/cri-o/cri-o/blob/main/pkg/config/workloads.go#L103-L107
- https://github.com/cri-o/cri-o/commit/75effcb1a25851a736e82dba1f7d8cee93ee159e
- https://github.com/cri-o/cri-o/pull/4479
- https://github.com/cri-o/cri-o/security/advisories/GHSA-p4rx-7wvg-fwrc
- https://nvd.nist.gov/vuln/detail/CVE-2023-6476
- https://www.cve.org/CVERecord?id=CVE-2023-6476
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2024:0195 | vendor-advisoryx_refsource_REDHATVendor Advisory | |
| https://access.redhat.com/errata/RHSA-2024:0207 | vendor-advisoryx_refsource_REDHATVendor Advisory | |
| https://access.redhat.com/security/cve/CVE-2023-6476 | vdb-entryx_refsource_REDHATVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2253994 | issue-trackingx_refsource_REDHATIssue TrackingVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-0390 | Advisory | |
| https://github.com/advisories/GHSA-p4rx-7wvg-fwrc | Advisory | |
| https://github.com/cri-o/cri-o/blob/main/pkg/config/workloads.go#L103-L107 | ||
| https://github.com/cri-o/cri-o/commit/75effcb1a25851a736e82dba1f7d8cee93ee159e | ||
| https://github.com/cri-o/cri-o/pull/4479 | ||
| https://github.com/cri-o/cri-o/security/advisories/GHSA-p4rx-7wvg-fwrc | ||
| https://nvd.nist.gov/vuln/detail/CVE-2023-6476 | ||
| https://www.cve.org/CVERecord?id=CVE-2023-6476 |
Change history (0)
No recorded changes yet.