CVE-2022-0532
published 2022-02-09CVE-2022-0532: An incorrect sysctls validation vulnerability was found in CRI-O 1.18 and earlier. The sysctls from the list of "safe" sysctls specified for the cluster will…
PriorityP420medium4.2CVSS 3.1
AVNACHPRLUINSUCLINAL
EPSS
0.77%
51.4th percentile
An incorrect sysctls validation vulnerability was found in CRI-O 1.18 and earlier. The sysctls from the list of "safe" sysctls specified for the cluster will be applied to the host if an attacker is able to create a pod with a hostIPC and hostNetwork kernel namespace.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | cri-o_cri-o | >= 0 < 1.23.1 | 1.23.1 |
| kubernetes | cri-o | <= 1.18 | — |
| kubernetes | cri-o | — | — |
| redhat | openshift_container_platform | — | — |
CVSS provenance
nvdv3.14.2MEDIUMCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:L
nvdv2.04.9MEDIUMAV:N/AC:M/Au:S/C:P/I:N/A:P
vendor_redhat4.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
cri-o: pod with access to 'hostIPC' and 'hostNetwork' kernel namespace allows sysctl from the list of safe sysctls to be applied to the host
vendor_redhat·2022-01-27·CVSS 4.2
CVE-2022-0532 [MEDIUM] CWE-732 cri-o: pod with access to 'hostIPC' and 'hostNetwork' kernel namespace allows sysctl from the list of safe sysctls to be applied to the host
cri-o: pod with access to 'hostIPC' and 'hostNetwork' kernel namespace allows sysctl from the list of safe sysctls to be applied to the host
An incorrect sysctls validation vulnerability was found in CRI-O 1.18 and earlier. The sysctls from the list of "safe" sysctls specified for the cluster will be applied to the host if an attacker is able to create a pod with a hostIPC and hostNetwork kernel namespace.
An incorrect sysctls validation vulnerability was found in CRI-O. The sysctls from the list of "safe" sysctls specified for the cluster [0] will be applied to the host if an attacker can create a pod with a `hostIPC` and `hostNetwork` kernel namespace.
Statement: Red Hat OpenShift Container Platform (OCP) uses a vulnerable version of CRI-O, but a successful exploit requires access to
OSV
Incorrect Permission Assignment for Critical Resource in CRI-O in github.com/cri-o/cri-o
osv·2024-08-21
CVE-2022-0532 Incorrect Permission Assignment for Critical Resource in CRI-O in github.com/cri-o/cri-o
Incorrect Permission Assignment for Critical Resource in CRI-O in github.com/cri-o/cri-o
Incorrect Permission Assignment for Critical Resource in CRI-O in github.com/cri-o/cri-o
GHSA
Incorrect Permission Assignment for Critical Resource in CRI-O
ghsa·2022-02-11
CVE-2022-0532 [MEDIUM] CWE-732 Incorrect Permission Assignment for Critical Resource in CRI-O
Incorrect Permission Assignment for Critical Resource in CRI-O
An incorrect sysctls validation vulnerability was found in CRI-O 1.18 and earlier. The sysctls from the list of "safe" sysctls specified for the cluster will be applied to the host if an attacker is able to create a pod with a hostIPC and hostNetwork kernel namespace.
OSV
Incorrect Permission Assignment for Critical Resource in CRI-O
osv·2022-02-11
CVE-2022-0532 [MEDIUM] Incorrect Permission Assignment for Critical Resource in CRI-O
Incorrect Permission Assignment for Critical Resource in CRI-O
An incorrect sysctls validation vulnerability was found in CRI-O 1.18 and earlier. The sysctls from the list of "safe" sysctls specified for the cluster will be applied to the host if an attacker is able to create a pod with a hostIPC and hostNetwork kernel namespace.
No detection rules found.
No public exploits indexed.
2022-02-09
Published