CVE-2022-4318
published 2026-07-15CVE-2022-4318: A flaw was found in CRI-O. The fix for a previous vulnerability (CVE-2022-4318) was incorrect, allowing it to be bypassed. An attacker capable of setting…
PriorityP342high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.27%
18.2th percentile
A flaw was found in CRI-O. The fix for a previous vulnerability (CVE-2022-4318) was incorrect, allowing it to be bypassed. An attacker capable of setting environment variables on a container can inject a newline character into the HOME environment variable. This issue allows the addition of arbitrary lines into /etc/passwd by use of a specially crafted environment variable.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fedoraproject | extra_packages_for_enterprise_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| github.com | cri-o_cri-o | >= 0 < 1.26.0 | 1.26.0 |
| kubernetes | cri-o | — | — |
| msrc | cbl2_cri-o_1.22.3-14_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_cri-o_1.22.3-1_on_cbl_mariner_2.0 | — | — |
| openshift-sandboxed-containers | osc-monitor-rhel9 | — | — |
| openshift4 | cnf-tests-rhel8 | — | — |
| openshift4 | ztp-site-generate-rhel8 | — | — |
| redhat | openshift_container_platform_for_arm64 | — | — |
| redhat | openshift_container_platform_for_arm64 | — | — |
| redhat | openshift_container_platform_for_linuxone | — | — |
| redhat | openshift_container_platform_for_linuxone | — | — |
| redhat | openshift_container_platform_for_power | — | — |
| redhat | openshift_container_platform_for_power | — | — |
| redhat | openshift_container_platform_ibm_z_systems | — | — |
| redhat | openshift_container_platform_ibm_z_systems | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
A flaw was found in CRI-O.
ghsa_unreviewed·2026-07-15·CVSS 7.8
CVE-2026-15809 [HIGH] CWE-116 A flaw was found in CRI-O.
A flaw was found in CRI-O. The fix for a previous vulnerability (CVE-2022-4318) was incorrect, allowing it to be bypassed. An attacker capable of setting environment variables on a container can inject a newline character into the HOME environment variable. This issue allows the addition of arbitrary lines into /etc/passwd by use of a specially crafted environment variable.
OSV
CRI-O vulnerable to /etc/passwd tampering resulting in Privilege Escalation in github.com/cri-o/cri-o
osv·2024-08-21
CVE-2022-4318 CRI-O vulnerable to /etc/passwd tampering resulting in Privilege Escalation in github.com/cri-o/cri-o
CRI-O vulnerable to /etc/passwd tampering resulting in Privilege Escalation in github.com/cri-o/cri-o
CRI-O vulnerable to /etc/passwd tampering resulting in Privilege Escalation in github.com/cri-o/cri-o
OSV
CRI-O vulnerable to /etc/passwd tampering resulting in Privilege Escalation
osv·2022-12-29
CVE-2022-4318 [MEDIUM] CRI-O vulnerable to /etc/passwd tampering resulting in Privilege Escalation
CRI-O vulnerable to /etc/passwd tampering resulting in Privilege Escalation
### Impact
It is possible to craft an environment variable with newlines to add entries to a container's /etc/passwd. It is possible to circumvent admission validation of username/UID by adding such an entry.
Note: because the pod author is in control of the container's /etc/passwd, this is not considered a new risk factor. However, this advisory is being opened for transparency and as a way of tracking fixes.
### Patches
1.26.0 will have the fix. More patches will be posted as they're available.
### Workarounds
Additional security controls like SELinux should prevent any damage a container is able to do with root on the host. Using SELinux is recommended because this class of attack is already possible by manu
GHSA
CRI-O vulnerable to /etc/passwd tampering resulting in Privilege Escalation
ghsa·2022-12-29
CVE-2022-4318 [MEDIUM] CWE-538 CRI-O vulnerable to /etc/passwd tampering resulting in Privilege Escalation
CRI-O vulnerable to /etc/passwd tampering resulting in Privilege Escalation
### Impact
It is possible to craft an environment variable with newlines to add entries to a container's /etc/passwd. It is possible to circumvent admission validation of username/UID by adding such an entry.
Note: because the pod author is in control of the container's /etc/passwd, this is not considered a new risk factor. However, this advisory is being opened for transparency and as a way of tracking fixes.
### Patches
1.26.0 will have the fix. More patches will be posted as they're available.
### Workarounds
Additional security controls like SELinux should prevent any damage a container is able to do with root on the host. Using SELinux is recommended because this class of attack is already possible by manu
Red Hat
github.com/cri-o/cri-o: Fix Bypass for CVE-2022-4318 — /etc/passwd Injection via HOME env
vendor_redhat·2026-07-15·CVSS 7.8
CVE-2026-15809 [HIGH] github.com/cri-o/cri-o: Fix Bypass for CVE-2022-4318 — /etc/passwd Injection via HOME env
github.com/cri-o/cri-o: Fix Bypass for CVE-2022-4318 — /etc/passwd Injection via HOME env
A flaw was found in CRI-O. The fix for a previous vulnerability (CVE-2022-4318) was incorrect, allowing it to be bypassed. An attacker capable of setting environment variables on a container can inject a newline character into the HOME environment variable. This issue allows the addition of arbitrary lines into /etc/passwd by use of a specially crafted environment variable.
Statement: This Important flaw in CRI-O allows for arbitrary line injection into a container's `/etc/passwd` file. An attacker capable of setting container environment variables can bypass a previous fix (CVE-2022-4318) by supplying a real newline character in the `HOME` environment variable, potentially leading to privilege esca
Microsoft
Cri-o: /etc/passwd tampering privesc
vendor_msrc·2023-09-12·CVSS 7.8
CVE-2022-4318 [HIGH] CWE-538 Cri-o: /etc/passwd tampering privesc
Cri-o: /etc/passwd tampering privesc
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com/en
Red Hat
cri-o: /etc/passwd tampering privesc
vendor_redhat·2022-12-12·CVSS 7.8
CVE-2022-4318 [HIGH] CWE-538 cri-o: /etc/passwd tampering privesc
cri-o: /etc/passwd tampering privesc
A vulnerability was found in cri-o. This issue allows the addition of arbitrary lines into /etc/passwd by use of a specially crafted environment variable.
A vulnerability was found in cri-o. This issue allows the addition of arbitrary lines into /etc/passwd by use of a specially crafted environment variable.
Package: fence-agents (Red Hat Enterprise Linux 9) - Not affected
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-15809 cri-o1.36: Fix Bypass for CVE-2022-4318 — /etc/passwd Injection via HOME env [fedora-all]
bugzilla·2026-07-15·CVSS 7.8
CVE-2026-15809 [HIGH] CVE-2026-15809 cri-o1.36: Fix Bypass for CVE-2022-4318 — /etc/passwd Injection via HOME env [fedora-all]
CVE-2026-15809 cri-o1.36: Fix Bypass for CVE-2022-4318 — /etc/passwd Injection via HOME env [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The fix for CVE-2022-4318 in CRI-O is incorrect and has been bypassable since it was introduced on December 14, 2022. The check in server/container_create.go uses a Go raw string literal (`\n`) instead of an interpreted string literal ("\n"), causing it to search for the literal two-character sequence backslash-n (0x5c 0x6e) rather than an actual newline character (0x0a).
An attacker who can set environment variables on a container (via the CRI CreateContainer req
Bugzilla
CVE-2026-15809 cri-o1.30: Fix Bypass for CVE-2022-4318 — /etc/passwd Injection via HOME env [fedora-all]
bugzilla·2026-07-15·CVSS 7.8
CVE-2026-15809 [HIGH] CVE-2026-15809 cri-o1.30: Fix Bypass for CVE-2022-4318 — /etc/passwd Injection via HOME env [fedora-all]
CVE-2026-15809 cri-o1.30: Fix Bypass for CVE-2022-4318 — /etc/passwd Injection via HOME env [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The fix for CVE-2022-4318 in CRI-O is incorrect and has been bypassable since it was introduced on December 14, 2022. The check in server/container_create.go uses a Go raw string literal (`\n`) instead of an interpreted string literal ("\n"), causing it to search for the literal two-character sequence backslash-n (0x5c 0x6e) rather than an actual newline character (0x0a).
An attacker who can set environment variables on a container (via the CRI CreateContainer req
Bugzilla
CVE-2026-15809 cri-o1.34: Fix Bypass for CVE-2022-4318 — /etc/passwd Injection via HOME env [fedora-all]
bugzilla·2026-07-15·CVSS 7.8
CVE-2026-15809 [HIGH] CVE-2026-15809 cri-o1.34: Fix Bypass for CVE-2022-4318 — /etc/passwd Injection via HOME env [fedora-all]
CVE-2026-15809 cri-o1.34: Fix Bypass for CVE-2022-4318 — /etc/passwd Injection via HOME env [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The fix for CVE-2022-4318 in CRI-O is incorrect and has been bypassable since it was introduced on December 14, 2022. The check in server/container_create.go uses a Go raw string literal (`\n`) instead of an interpreted string literal ("\n"), causing it to search for the literal two-character sequence backslash-n (0x5c 0x6e) rather than an actual newline character (0x0a).
An attacker who can set environment variables on a container (via the CRI CreateContainer req
Bugzilla
CVE-2026-15809 github.com/cri-o/cri-o: Fix Bypass for CVE-2022-4318 — /etc/passwd Injection via HOME env
bugzilla·2026-07-15·CVSS 7.8
CVE-2026-15809 [HIGH] CVE-2026-15809 github.com/cri-o/cri-o: Fix Bypass for CVE-2022-4318 — /etc/passwd Injection via HOME env
CVE-2026-15809 github.com/cri-o/cri-o: Fix Bypass for CVE-2022-4318 — /etc/passwd Injection via HOME env
The fix for CVE-2022-4318 in CRI-O is incorrect and has been bypassable since it was introduced on December 14, 2022. The check in server/container_create.go uses a Go raw string literal (`\n`) instead of an interpreted string literal ("\n"), causing it to search for the literal two-character sequence backslash-n (0x5c 0x6e) rather than an actual newline character (0x0a).
An attacker who can set environment variables on a container (via the CRI CreateContainer request) can supply a real newline character in the HOME environment variable, bypassing the check entirely. The unsanitized value is
then passed to utils.GeneratePasswd, which uses fmt.Sprintf to construct the container's /etc/
Bugzilla
CVE-2026-15809 cri-o: Fix Bypass for CVE-2022-4318 — /etc/passwd Injection via HOME env [fedora-all]
bugzilla·2026-07-15·CVSS 7.8
CVE-2026-15809 [HIGH] CVE-2026-15809 cri-o: Fix Bypass for CVE-2022-4318 — /etc/passwd Injection via HOME env [fedora-all]
CVE-2026-15809 cri-o: Fix Bypass for CVE-2022-4318 — /etc/passwd Injection via HOME env [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The fix for CVE-2022-4318 in CRI-O is incorrect and has been bypassable since it was introduced on December 14, 2022. The check in server/container_create.go uses a Go raw string literal (`\n`) instead of an interpreted string literal ("\n"), causing it to search for the literal two-character sequence backslash-n (0x5c 0x6e) rather than an actual newline character (0x0a).
An attacker who can set environment variables on a container (via the CRI CreateContainer request
Bugzilla
CVE-2026-15809 cri-o1.35: Fix Bypass for CVE-2022-4318 — /etc/passwd Injection via HOME env [fedora-all]
bugzilla·2026-07-15·CVSS 7.8
CVE-2026-15809 [HIGH] CVE-2026-15809 cri-o1.35: Fix Bypass for CVE-2022-4318 — /etc/passwd Injection via HOME env [fedora-all]
CVE-2026-15809 cri-o1.35: Fix Bypass for CVE-2022-4318 — /etc/passwd Injection via HOME env [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The fix for CVE-2022-4318 in CRI-O is incorrect and has been bypassable since it was introduced on December 14, 2022. The check in server/container_create.go uses a Go raw string literal (`\n`) instead of an interpreted string literal ("\n"), causing it to search for the literal two-character sequence backslash-n (0x5c 0x6e) rather than an actual newline character (0x0a).
An attacker who can set environment variables on a container (via the CRI CreateContainer req
Bugzilla
CVE-2026-15809 cri-o1.33: Fix Bypass for CVE-2022-4318 — /etc/passwd Injection via HOME env [fedora-all]
bugzilla·2026-07-15·CVSS 7.8
CVE-2026-15809 [HIGH] CVE-2026-15809 cri-o1.33: Fix Bypass for CVE-2022-4318 — /etc/passwd Injection via HOME env [fedora-all]
CVE-2026-15809 cri-o1.33: Fix Bypass for CVE-2022-4318 — /etc/passwd Injection via HOME env [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The fix for CVE-2022-4318 in CRI-O is incorrect and has been bypassable since it was introduced on December 14, 2022. The check in server/container_create.go uses a Go raw string literal (`\n`) instead of an interpreted string literal ("\n"), causing it to search for the literal two-character sequence backslash-n (0x5c 0x6e) rather than an actual newline character (0x0a).
An attacker who can set environment variables on a container (via the CRI CreateContainer req
Bugzilla
CVE-2026-15809 cri-o1.31: Fix Bypass for CVE-2022-4318 — /etc/passwd Injection via HOME env [fedora-all]
bugzilla·2026-07-15·CVSS 7.8
CVE-2026-15809 [HIGH] CVE-2026-15809 cri-o1.31: Fix Bypass for CVE-2022-4318 — /etc/passwd Injection via HOME env [fedora-all]
CVE-2026-15809 cri-o1.31: Fix Bypass for CVE-2022-4318 — /etc/passwd Injection via HOME env [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The fix for CVE-2022-4318 in CRI-O is incorrect and has been bypassable since it was introduced on December 14, 2022. The check in server/container_create.go uses a Go raw string literal (`\n`) instead of an interpreted string literal ("\n"), causing it to search for the literal two-character sequence backslash-n (0x5c 0x6e) rather than an actual newline character (0x0a).
An attacker who can set environment variables on a container (via the CRI CreateContainer req
Bugzilla
CVE-2026-15809 cri-o1.32: Fix Bypass for CVE-2022-4318 — /etc/passwd Injection via HOME env [fedora-all]
bugzilla·2026-07-15·CVSS 7.8
CVE-2026-15809 [HIGH] CVE-2026-15809 cri-o1.32: Fix Bypass for CVE-2022-4318 — /etc/passwd Injection via HOME env [fedora-all]
CVE-2026-15809 cri-o1.32: Fix Bypass for CVE-2022-4318 — /etc/passwd Injection via HOME env [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The fix for CVE-2022-4318 in CRI-O is incorrect and has been bypassable since it was introduced on December 14, 2022. The check in server/container_create.go uses a Go raw string literal (`\n`) instead of an interpreted string literal ("\n"), causing it to search for the literal two-character sequence backslash-n (0x5c 0x6e) rather than an actual newline character (0x0a).
An attacker who can set environment variables on a container (via the CRI CreateContainer req
2026-07-15
Published