cbcvebase.
CVE-2022-4318
published 2026-07-15

CVE-2022-4318: A flaw was found in CRI-O. The fix for a previous vulnerability (CVE-2022-4318) was incorrect, allowing it to be bypassed. An attacker capable of setting…

PriorityP342high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.27%
18.2th percentile
A flaw was found in CRI-O. The fix for a previous vulnerability (CVE-2022-4318) was incorrect, allowing it to be bypassed. An attacker capable of setting environment variables on a container can inject a newline character into the HOME environment variable. This issue allows the addition of arbitrary lines into /etc/passwd by use of a specially crafted environment variable.

Affected

18 ranges
VendorProductVersion rangeFixed in
fedoraprojectextra_packages_for_enterprise_linux
fedoraprojectfedora
fedoraprojectfedora
github.comcri-o_cri-o>= 0 < 1.26.01.26.0
kubernetescri-o
msrccbl2_cri-o_1.22.3-14_on_cbl_mariner_2.0
msrccbl2_cri-o_1.22.3-1_on_cbl_mariner_2.0
openshift-sandboxed-containersosc-monitor-rhel9
openshift4cnf-tests-rhel8
openshift4ztp-site-generate-rhel8
redhatopenshift_container_platform_for_arm64
redhatopenshift_container_platform_for_arm64
redhatopenshift_container_platform_for_linuxone
redhatopenshift_container_platform_for_linuxone
redhatopenshift_container_platform_for_power
redhatopenshift_container_platform_for_power
redhatopenshift_container_platform_ibm_z_systems
redhatopenshift_container_platform_ibm_z_systems

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.