Back

HIGH

Cri-o: pods are able to break out of resource confinement on cgroupv2

Published Jan 9, 2024

Description

A flaw was found in CRI-O that involves an experimental annotation leading to a container being unconfined. This may allow a pod to specify and get any amount of memory/cpu, circumventing the kubernetes scheduler and potentially resulting in a denial of service in the node.

Affected products

Remediation

Red Hat statement

There are two main factors reduce the severity of this vulnerability to Moderate: * A potential attacker must already have valid credentials * The OpenShift environment must already be configured to use an experimental feature

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jan 9, 2024
Updated Nov 20, 2025
Reserved Dec 4, 2023
CISA Vulnrichment
Updated Jan 10, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jan 9, 2024
ENISA EUVD
Assigner redhat
Published Jan 9, 2024
Updated Nov 20, 2025
Exploited since n/a
EUVD-2024-0390 GHSA-P4RX-7WVG-FWRC