A vulnerability in CRI-O allows root access to the host environment

In CRI-O, a runtime for managing isolated containers, a critical vulnerability (CVE-2022-0811) has been identified that allows isolation to be bypassed and code to be executed on the host system. If CRI-O is used instead of containerd and Docker to manage the execution of containers running on the Kubernetes platform, an attacker could gain control over any node in the Kubernetes cluster. To conduct the attack, it is sufficient to have permissions to run their own container in the Kubernetes cluster.

The vulnerability is caused by the ability to modify the kernel sysctl parameter "kernel.core_pattern" ("/proc/sys/kernel/core_pattern"), which was accessible without restrictions, despite not being among the safe parameters that only apply within the namespace of the current container. Using this parameter, a user from the container can alter the Linux kernel's behavior regarding core file handling on the host environment and launch arbitrary commands with root privileges on the host by specifying a handler like "|/bin/sh -c 'commands'".

The issue has been present since the release of CRI-O 1.19.0 and has been resolved in updates 1.19.6, 1.20.7, 1.21.6, 1.22.3, 1.23.2, and 1.24.0. The problem appears in distributions in Red Hat OpenShift Container Platform and openSUSE/SUSE, where the cri-o package is available in their repositories.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster