Improper authorization control for web services In github.com/cri-o/cri-o
Description
CRI-O: Maliciously structured checkpoint file can gain arbitrary node access
Patches
1.31.1, 1.30.6, 1.29.8
Workarounds
set enable_criu_support = false
References
Are there any links users can visit to find out more?
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
go | 1.29.11, 1.30.8, 1.31.3 | ||
rpm rhel8 | - | - | |
rpm rhel9 | - | - |
Aliases
1. 2. 3. 4. 5. 6. 7. 8. 9. 10. 11. 12.
References
1. 2. 3.