logo

CVE-2022-0811: CRI-O Vulnerability Could Allow Container Escape

ID: 170f084a-318c-5605-9043-0fe69260e701

STIX ID: report--170f084a-318c-5605-9043-0fe69260e701

Feed Name: Aqua Security Blog

Threat Score
70/100

Date Published: 2022-03-17

Date Updated: 2026-04-26

...
...

This report describes a CRI-O vulnerability that permits container breakout by abusing malformed sysctls in Kubernetes/OpenShift pod manifests; a reproducible proof-of-concept and demonstrations of full node compromise are referenced. It recommends patching as the primary fix and provides practical interim mitigations using admission controllers (Gatekeeper and Kyverno) to block custom sysctls until fixes can be deployed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.