cbcvebase.
CVE-2023-6476
published 2024-01-09

CVE-2023-6476: A flaw was found in CRI-O that involves an experimental annotation leading to a container being unconfined. This may allow a pod to specify and get any amount…

PriorityP336high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.86%
54.4th percentile
A flaw was found in CRI-O that involves an experimental annotation leading to a container being unconfined. This may allow a pod to specify and get any amount of memory/cpu, circumventing the kubernetes scheduler and potentially resulting in a denial of service in the node.

Affected

8 ranges
VendorProductVersion rangeFixed in
github.comcri-o_cri-o>= 0 < 1.27.31.27.3
github.comcri-o_cri-o>= 1.28.0 < 1.28.31.28.3
github.comcri-o_cri-o>= 1.29.0 < 1.29.11.29.1
msrccbl2_cri-o_1.22.3-10_on_cbl_mariner_2.0
msrccbl2_cri-o_1.22.3-14_on_cbl_mariner_2.0
redhatopenshift_container_platform
redhatopenshift_container_platform
redhatopenshift_container_platform

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_msrc6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.