cbcvebase.
CVE-2023-6476
published 2024-01-09

CVE-2023-6476: A flaw was found in CRI-O that involves an experimental annotation leading to a container being unconfined. This may allow a pod to specify and get any amount…

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
A flaw was found in CRI-O that involves an experimental annotation leading to a container being unconfined. This may allow a pod to specify and get any amount of memory/cpu, circumventing the kubernetes scheduler and potentially resulting in a denial of service in the node.

Affected

8 ranges
VendorProductVersion rangeFixed in
github.comcri-o_cri-o>= 0 < 1.27.31.27.3
github.comcri-o_cri-o>= 1.28.0 < 1.28.31.28.3
github.comcri-o_cri-o>= 1.29.0 < 1.29.11.29.1
msrccbl2_cri-o_1.22.3-10_on_cbl_mariner_2.0
msrccbl2_cri-o_1.22.3-14_on_cbl_mariner_2.0
redhatopenshift_container_platform
redhatopenshift_container_platform
redhatopenshift_container_platform