Code Injection in CRI-O - CVE-2022-0811
Published: March 17, 2022 / Updated: May 4, 2022
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a container escape flaw related to kernel options setting for a pod. A remote user can send a specially crafted request and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
cri-o (Red Hat package)
haproxy (Red Hat package)
openshift-ansible (Red Hat package)
openshift-clients (Red Hat package)
openshift-kuryr (Red Hat package)
openshift (Red Hat package)
atomic-openshift-service-idler (Red Hat package)
jenkins-2-plugins (Red Hat package)
cri-o
Red Hat OpenShift GitOps
Red Hat OpenShift Container Platform
IBM Netezza for Cloud Pak for Data
Fedora
Red Hat Advanced Cluster Management for Kubernetes
How to mitigate CVE-2022-0811
cri-o (Red Hat package) - addressed in versions 1.19.5-3.rhaos4.6.git91f8458.el7, 1.19.5-3.rhaos4.6.git91f8458.el8, 1.20.6-11.rhaos4.7.git76ea3d0.el7, 1.20.6-11.rhaos4.7.git76ea3d0.el8, 1.21.5-3.rhaos4.8.gitaf64931.el7, 1.21.5-3.rhaos4.8.gitaf64931.el8, 1.22.2-3.rhaos4.9.gitb030be8.el7, 1.22.2-3.rhaos4.9.gitb030be8.el8, 1.23.1-12.rhaos4.10.git1607c6e.el7, 1.23.1-12.rhaos4.10.git1607c6e.el8
Red Hat OpenShift GitOps - update to 1.3.6
haproxy (Red Hat package) - update to 2.2.19-2.el8
Red Hat OpenShift Container Platform - addressed in versions 4.6.56, 4.7.45, 4.8.35, 4.9.25, 4.10.4
openshift-ansible (Red Hat package) - addressed in versions 4.6.0-202202251050.p0.g87e9f0c.assembly.stream.el7, 4.8.0-202203100145.p0.gfccb320.assembly.stream.el7
openshift-clients (Red Hat package) - addressed in versions 4.6.0-202203011423.p0.gb153f08.assembly.stream.el7, 4.6.0-202203011423.p0.gb153f08.assembly.stream.el8, 4.7.0-202202231953.p0.gc4ebc7a.assembly.stream.el7, 4.7.0-202202231953.p0.gc4ebc7a.assembly.stream.el8, 4.9.0-202203112019.p0.g1791fd4.assembly.stream.el7, 4.9.0-202203112019.p0.g1791fd4.assembly.stream.el8
openshift-kuryr (Red Hat package) - update to 4.6.0-202202251050.p0.g74cd766.assembly.stream.el8
openshift (Red Hat package) - addressed in versions 4.6.0-202203110946.p0.g6175753.assembly.stream.el7, 4.6.0-202203110946.p0.g6175753.assembly.stream.el8, 4.7.0-202203091647.p0.g0d60930.assembly.stream.el7, 4.7.0-202203091647.p0.g0d60930.assembly.stream.el8, 4.8.0-202203100757.p0.gee73ea2.assembly.stream.el7, 4.8.0-202203100757.p0.gee73ea2.assembly.stream.el8
atomic-openshift-service-idler (Red Hat package) - update to 4.6.0-202202251050.p0.g39cfc66.assembly.stream.el8
jenkins-2-plugins (Red Hat package) - update to 4.8.1646993358-1.el8
IBM Netezza for Cloud Pak for Data - update to 11.2.1.6
cri-o - addressed in versions 1.20-3420220323184337.058368ca, 1.20-3520220323184337.f27b74a8, 1.20-3620220323184337.5e5ad4a0, 1.22-3420220315182248.058368ca, 1.22-3520220315182248.f27b74a8, 1.22-3620220315182248.5e5ad4a0
Red Hat Advanced Cluster Management for Kubernetes - update to 2.4.3
External References
Related Security Bulletins
- Remote code execution in CRI-O
- Red Hat OpenShift Container Platform 4.10 update for CRI-O
- Remote code execution in OpenShift Container Platform 4.8
- Remote code execution in OpenShift Container Platform 4.7
- Remote code execution in OpenShift Container Platform 4.9
- Remote code execution in OpenShift Container Platform 4.6
- Multiple vulnerabilities in Red Hat OpenShift GitOps 1.3
- Remote code execution in IBM Netezza for Cloud Pak for Data
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.4
- Fedora 36 Modular update for cri-o
- Fedora 35 Modular update for cri-o
- Fedora 34 Modular update for cri-o
- Fedora 35 Modular update for cri-o
- Fedora 36 Modular update for cri-o
- Fedora 34 Modular update for cri-o