Skip to content

containerd CVE-2022-23648

Moderate
arnaldo2792 published GHSA-hmxq-qpgg-r69g Mar 2, 2022

Package

containerd (bottlerocket)

Affected versions

< 1.6.1

Patched versions

1.6.1

Description

A bug was found in containerd where containers launched through containerd’s CRI implementation with a specially-crafted image configuration could gain access to read-only copies of arbitrary files and directories on the host. This may bypass any policy-based enforcement on container setup (including a Kubernetes Pod Security Policy) and expose potentially sensitive information. Kubernetes and crictl can both be configured to use containerd’s CRI implementation.

For more information, please refer to GHSA-crp2-qrr5-8pq7.

Severity

Moderate

CVE ID

CVE-2022-23648

Weaknesses

No CWEs