PT-2022-7296 · Cri-O+2 · Cri-O+2

·

CVE-2022-4318

·

Published

2022-12-23

·

Updated

2026-07-27

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions cri-o versions prior to 1.26.0
Description A flaw exists that allows the addition of arbitrary lines into a container's /etc/passwd file by using a specially crafted environment variable containing newlines. This can be used to bypass admission validation of the username or UID. This issue may impact the confidentiality, integrity, and availability of protected information.
Recommendations Update to version 1.26.0. Use SELinux as an additional security control to prevent potential damage a container can cause with root privileges on the host.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2023-1519
ALT-PU-2023-1528
AZL-39873
BDU:2024-02430
CVE-2022-4318
GHSA-CM9X-C3RH-7RC4
GO-2022-1206
OESA-2024-1406
RHSA-2023:1033
RHSA-2023:1503

Affected Products

Alt Linux
Red Os
Cri-O