Kubernetes
Kubernetes Cri-o: vulnerabilidades y CVE
Kubernetes Cri-o tiene 20 vulnerabilidades publicadas, 6 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE20
Últimos 12 meses6
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-62146 | Alta (7.8) | 0.11% | — | 30 sept 2026 | A trust-boundary flaw in CRI-O's sandbox state persistence allows attacker-influenced pod metadata to overwrite CRI-O's own reserved sandbox bookkeeping; once reloaded as trusted after a restart, a later container… |
| CVE-2026-92574 | Alta (8.8) | 0.65% | — | 21 sept 2026 | A vulnerability in CRI-O checkpoint restore allows a user who can create a pod from a malicious checkpointed container to bypass the destination Kubernetes security context. The restored process may retain credentials,… |
| CVE-2026-15801 | Alta (8) | 0.32% | — | 21 sept 2026 | A vulnerability was found in CRI-O related to the container checkpoint and restore feature. When CRI-O is configured to restore containers from checkpoint archives, insufficient validation of restore metadata may allow… |
| CVE-2026-17113 | Media (6) | 0.11% | — | 24 ago 2026 | A flaw was found in CRI-O's container-creation environment-variable handling (`mergeEnvs` in `server/utils.go`, consumed by `setupContainerEnvironmentAndWorkdir` in `server/container_create.go`). When a… |
| CVE-2026-13622 | Alta (8.8) | 0.20% | — | 12 ago 2026 | A symlink following vulnerability was found in KubeVirt's virt-handler migration proxy. During live migration, virt-handler dials Unix sockets inside the target virt-launcher pod via /proc/<pid>/root/ paths using… |
| CVE-2026-15809 | Alta (7.8) | 0.18% | — | 15 jul 2026 | A flaw was found in CRI-O. The fix for a previous vulnerability (CVE-2022-4318) was incorrect, allowing it to be bypassed. An attacker capable of setting environment variables on a container can inject a newline… |
| CVE-2025-4437 | Media (5.7) | 0.25% | — | 20 ago 2025 | There's a vulnerability in the CRI-O application where when container is launched with securityContext.runAsUser specifying a non-existent user, CRI-O attempts to create the user, reading the container's entire… |
| CVE-2025-0750 | Media (6.6) | 0.24% | — | 28 ene 2025 | A vulnerability was found in CRI-O. A path traversal issue in the log management functions (UnMountPodLogs and LinkContainerLogs) may allow an attacker with permissions to create and delete Pods to unmount arbitrary… |
| CVE-2024-8676 | Alta (7.4) | 0.75% | — | 26 nov 2024 | A vulnerability was found in CRI-O, where it can be requested to take a checkpoint archive of a container and later be asked to restore it. When it does that restoration, it attempts to restore the mounts from the… |
| CVE-2024-5154 | Alta (8.1) | 1.2% | — | 12 jun 2024 | A flaw was found in cri-o. A malicious container can create a symbolic link to arbitrary files on the host via directory traversal (“../“). This flaw allows the container to read and write to arbitrary files on the host… |
| CVE-2024-3154 | Alta (7.2) | 1.4% | — | 26 abr 2024 | A flaw was found in cri-o, where an arbitrary systemd property can be injected via a Pod annotation. Any user who can create a pod with an arbitrary annotation may perform an arbitrary action on the host system. |
| CVE-2022-4318 | Alta (7.8) | 0.29% | — | 25 sept 2023 | A vulnerability was found in cri-o. This issue allows the addition of arbitrary lines into /etc/passwd by use of a specially crafted environment variable. |
| CVE-2022-3466 | Media (5.3) | 0.21% | — | 15 sept 2023 | The version of cri-o as released for Red Hat OpenShift Container Platform 4.9.48, 4.10.31, and 4.11.6 via RHBA-2022:6316, RHBA-2022:6257, and RHBA-2022:6658, respectively, included an incorrect version of cri-o missing… |
| CVE-2022-2995 | Alta (7.1) | 0.39% | — | 19 sept 2022 | Incorrect handling of the supplementary groups in the CRI-O container engine might lead to sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where… |
| CVE-2022-1708 | Alta (7.5) | 3.2% | — | 7 jun 2022 | A vulnerability was found in CRI-O that causes memory or disk space exhaustion on the node for anyone with access to the Kube API. The ExecSync request runs commands in a container and logs the output of the command.… |
| CVE-2022-27652 | Media (5.3) | 0.24% | — | 18 abr 2022 | A flaw was found in cri-o, where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers started incorrectly with non-empty inheritable… |
| CVE-2022-0811 | Alta (8.8) | 19% | — | 16 mar 2022 | A flaw was found in CRI-O in the way it set kernel options for a pod. This issue allows anyone with rights to deploy a pod on a Kubernetes cluster that uses the CRI-O runtime to achieve a container escape and arbitrary… |
| CVE-2022-0532 | Media (4.2) | 0.77% | — | 9 feb 2022 | An incorrect sysctls validation vulnerability was found in CRI-O 1.18 and earlier. The sysctls from the list of "safe" sysctls specified for the cluster will be applied to the host if an attacker is able to create a pod… |
| CVE-2019-14891 | Media (5) | 0.80% | — | 25 nov 2019 | A flaw was found in cri-o, as a result of all pod-related processes being placed in the same memory cgroup. This can result in container management (conmon) processes being killed if a workload process triggers an… |
| CVE-2018-1000400 | Alta (8.8) | 2.0% | — | 18 may 2018 | Kubernetes CRI-O version prior to 1.9 contains a Privilege Context Switching Error (CWE-270) vulnerability in the handling of ambient capabilities that can result in containers running with elevated privileges, allowing… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.