Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2841▼ 157 respecto a la semana anterior
Críticas / altas1370▲ 51 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
20 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.8) | 0.11% | — | Kubernetes Cri-oAI | 30/9/2026 | 30/9/2026 | A trust-boundary flaw in CRI-O's sandbox state persistence allows attacker-influenced pod metadata to overwrite CRI-O's own reserved sandbox bookkeeping; once reloaded as trusted after a restart, a later container recreate in that sandbox can expose a host-side runtime-management resource inside the container,… | |
| Pendiente de análisis | Alta (8.8) | 0.65% | — | Redhat Openshift Container PlatformAIKubernetes Cri-oAI | 21/9/2026 | 1/10/2026 | A vulnerability in CRI-O checkpoint restore allows a user who can create a pod from a malicious checkpointed container to bypass the destination Kubernetes security context. The restored process may retain credentials, Linux capabilities, no_new_privs, and seccomp state from the checkpoint instead of enforcing the… | |
| Pendiente de análisis | Alta (8) | 0.32% | — | Kubernetes Cri-oAI | 21/9/2026 | 22/9/2026 | A vulnerability was found in CRI-O related to the container checkpoint and restore feature. When CRI-O is configured to restore containers from checkpoint archives, insufficient validation of restore metadata may allow a user with sufficient privileges to perform unintended operations on the host filesystem.… | |
| Pendiente de análisis | Media (6) | 0.11% | — | Kubernetes Cri-oAI | 24/8/2026 | 28/8/2026 | A flaw was found in CRI-O's container-creation environment-variable handling (`mergeEnvs` in `server/utils.go`, consumed by `setupContainerEnvironmentAndWorkdir` in `server/container_create.go`). When a `CreateContainer` request supplies a `nil` CRI `Envs` field, CRI-O falls back to using the target OCI image's… | |
| Pendiente de análisis | Alta (8.8) | 0.20% | — | KubevirtAIKubernetes Cri-oAI | 12/8/2026 | 21/9/2026 | A symlink following vulnerability was found in KubeVirt's virt-handler migration proxy. During live migration, virt-handler dials Unix sockets inside the target virt-launcher pod via /proc/<pid>/root/ paths using net.Dial() without symlink protection. These socket paths reside in qemu-owned directories writable by the… | |
| Aplazada | Alta (7.8) | 0.18% | — | Kubernetes Cri-oAI | 15/7/2026 | 1/10/2026 | A flaw was found in CRI-O. The fix for a previous vulnerability (CVE-2022-4318) was incorrect, allowing it to be bypassed. An attacker capable of setting environment variables on a container can inject a newline character into the HOME environment variable. This issue allows the addition of arbitrary lines into… | |
| Aplazada | Media (5.7) | 0.25% | — | Kubernetes Cri-oAI | 20/8/2025 | 25/9/2026 | There's a vulnerability in the CRI-O application where when container is launched with securityContext.runAsUser specifying a non-existent user, CRI-O attempts to create the user, reading the container's entire /etc/passwd file into memory. If this file is excessively large, it can cause the a high memory consumption… | |
| Aplazada | Media (6.6) | 0.24% | — | Kubernetes Cri-oAI | 28/1/2025 | 17/6/2026 | A vulnerability was found in CRI-O. A path traversal issue in the log management functions (UnMountPodLogs and LinkContainerLogs) may allow an attacker with permissions to create and delete Pods to unmount arbitrary host paths, leading to node-level denial of service by unmounting critical system directories. | |
| Aplazada | Alta (7.4) | 0.75% | — | Kubernetes Cri-oAI | 26/11/2024 | 21/8/2026 | A vulnerability was found in CRI-O, where it can be requested to take a checkpoint archive of a container and later be asked to restore it. When it does that restoration, it attempts to restore the mounts from the restore archive instead of the pod request. As a result, the validations run on the pod spec, verifying… | |
| Modificada | Alta (8.1) | 1.2% | — | Kubernetes Cri-oRedhat Openshift Container Platform | 12/6/2024 | 21/8/2026 | A flaw was found in cri-o. A malicious container can create a symbolic link to arbitrary files on the host via directory traversal (“../“). This flaw allows the container to read and write to arbitrary files on the host system. | |
| Aplazada | Alta (7.2) | 1.4% | — | Kubernetes Cri-oAI | 26/4/2024 | 24/8/2026 | A flaw was found in cri-o, where an arbitrary systemd property can be injected via a Pod annotation. Any user who can create a pod with an arbitrary annotation may perform an arbitrary action on the host system. | |
| Modificada | Alta (7.8) | 0.29% | — | Kubernetes Cri-oRedhat Openshift Container Platform FOR Arm64Redhat Openshift Container Platform FOR LinuxoneRedhat Openshift Container Platform FOR Power+3 | 25/9/2023 | 17/6/2026 | A vulnerability was found in cri-o. This issue allows the addition of arbitrary lines into /etc/passwd by use of a specially crafted environment variable. | |
| Modificada | Media (5.3) | 0.21% | — | Kubernetes Cri-oRedhat Openshift Container Platform | 15/9/2023 | 17/6/2026 | The version of cri-o as released for Red Hat OpenShift Container Platform 4.9.48, 4.10.31, and 4.11.6 via RHBA-2022:6316, RHBA-2022:6257, and RHBA-2022:6658, respectively, included an incorrect version of cri-o missing the fix for CVE-2022-27652, which was previously fixed in OCP 4.9.41 and 4.10.12 via RHBA-2022:5433… | |
| Modificada | Alta (7.1) | 0.39% | — | Kubernetes Cri-o | 19/9/2022 | 17/6/2026 | Incorrect handling of the supplementary groups in the CRI-O container engine might lead to sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to set access permissions and is able to execute a binary code in that… | |
| Modificada | Alta (7.5) | 3.2% | — | Kubernetes Cri-oFedoraproject FedoraRedhat Openshift Container PlatformRedhat Enterprise Linux | 7/6/2022 | 17/6/2026 | A vulnerability was found in CRI-O that causes memory or disk space exhaustion on the node for anyone with access to the Kube API. The ExecSync request runs commands in a container and logs the output of the command. This output is then read by CRI-O after command execution, and it is read in a manner where the entire… | |
| Modificada | Media (5.3) | 0.24% | — | Kubernetes Cri-oFedoraproject FedoraMobyproject MobyRedhat Openshift Container Platform | 18/4/2022 | 17/6/2026 | A flaw was found in cri-o, where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable… | |
| Modificada | Alta (8.8) | 19% | — | Kubernetes Cri-o | 16/3/2022 | 17/6/2026 | A flaw was found in CRI-O in the way it set kernel options for a pod. This issue allows anyone with rights to deploy a pod on a Kubernetes cluster that uses the CRI-O runtime to achieve a container escape and arbitrary code execution as root on the cluster node, where the malicious pod was deployed. | |
| Modificada | Media (4.2) | 0.77% | — | Kubernetes Cri-oRedhat Openshift Container Platform | 9/2/2022 | 17/6/2026 | An incorrect sysctls validation vulnerability was found in CRI-O 1.18 and earlier. The sysctls from the list of "safe" sysctls specified for the cluster will be applied to the host if an attacker is able to create a pod with a hostIPC and hostNetwork kernel namespace. | |
| Modificada | Media (5) | 0.80% | — | Kubernetes Cri-oFedoraproject FedoraRedhat Openshift Container Platform | 25/11/2019 | 17/6/2026 | A flaw was found in cri-o, as a result of all pod-related processes being placed in the same memory cgroup. This can result in container management (conmon) processes being killed if a workload process triggers an out-of-memory (OOM) condition for the cgroup. An attacker could abuse this flaw to get host network… | |
| Modificada | Alta (8.8) | 2.0% | — | Kubernetes Cri-o | 18/5/2018 | 17/6/2026 | Kubernetes CRI-O version prior to 1.9 contains a Privilege Context Switching Error (CWE-270) vulnerability in the handling of ambient capabilities that can result in containers running with elevated privileges, allowing users abilities they should not have. This attack appears to be exploitable via container… |