CVE-2022-0811: CRI-O Vulnerability Could Allow Container Escape
ID: 170f084a-318c-5605-9043-0fe69260e701
STIX ID: report--170f084a-318c-5605-9043-0fe69260e701
Feed Name: Aqua Security Blog
Threat Score
This report describes a CRI-O vulnerability that permits container breakout by abusing malformed sysctls in Kubernetes/OpenShift pod manifests; a reproducible proof-of-concept and demonstrations of full node compromise are referenced. It recommends patching as the primary fix and provides practical interim mitigations using admission controllers (Gatekeeper and Kyverno) to block custom sysctls until fixes can be deployed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
