Lucene search

K
osvGoogleOSV:CVE-2022-0532
HistoryFeb 09, 2022 - 11:15 p.m.

CVE-2022-0532

2022-02-0923:15:16
Google
osv.dev
10
cri-o vulnerability
sysctls validation
hostipc
hostnetwork
kernel namespace

AI Score

6.4

Confidence

Low

EPSS

0.001

Percentile

31.4%

An incorrect sysctls validation vulnerability was found in CRI-O 1.18 and earlier. The sysctls from the list of “safe” sysctls specified for the cluster will be applied to the host if an attacker is able to create a pod with a hostIPC and hostNetwork kernel namespace.

AI Score

6.4

Confidence

Low

EPSS

0.001

Percentile

31.4%