Skip to content
VulniPulse
High8.1Red Hat Linux

High [CVE-2024-5154] Cri-o: malicious container can create symlink on host

This high-severity Red Hat Linux advisory covers CVE-2024-5154 affecting Red Hat OpenShift Container Platform 4.12, Red Hat OpenShift Container Platform 4.13, Red Hat OpenShift Container Platform 4.14.

CVE-2024-5154 Published Jun 12, 2024Updated by vendor May 27, 2024
Affected products & platforms
Red Hat LinuxUnclassified
Open vendor advisory

Android app · Google Play

Monitor future Red Hat Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

A flaw was found in cri-o. A malicious container can create a symbolic link to arbitrary files on the host via directory traversal (“../“).

This flaw allows the container to read and write to arbitrary files on the host system. Red Hat OpenShift Container Platform (OCP) includes the vulnerable cri-o library, however it does not load untrusted container, therefore impact is reduced to Important.

Red Hat severity: Important — CVSS 8.1 (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N). Weakness: CWE-22.

Affected Red Hat products: Red Hat OpenShift Container Platform 4.12; Red Hat OpenShift Container Platform 4.13; Red Hat OpenShift Container Platform 4.14; Red Hat OpenShift Container Platform 4.15; Red Hat OpenShift Container Platform 4.16; Red Hat OpenShift Container Platform 4.17; Red Hat OpenShift Container Platform 3.11.

Red Hat lists Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9 as not affected. Will not fix / out of support: Red Hat OpenShift Container Platform 3.11.

Red Hat fixing advisory: RHSA-2024:4008, RHSA-2024:4486, RHSA-2024:3700, RHSA-2024:3676, RHSA-2024:4159, RHSA-2024:10818.

Affected versions

No affected-version range was extracted from the source record. The vendor advisory is authoritative — check it before change work.

Official advisory · high-confidence parse· fetched 1 hour ago·verify at source

Fixed versions
  • cri-o-0:1.25.5-21.2.rhaos4.12.gita3eb75f.el8
  • cri-o-0:1.26.5-18.2.rhaos4.13.git2e90133.el8
  • cri-o-0:1.27.7-3.rhaos4.14.git674563e.el8
  • cri-o-0:1.28.7-2.rhaos4.15.git111aec5.el8
  • cri-o-0:1.29.5-7.rhaos4.16.git7db4ada.el8
  • kernel-0:5.14.0-427.24.1.el9_4
  • openshift-0:4.16.0-202406191607.p0.g58452d8.assembly.stream.el8
  • rhcos-417.94.202412040832-0
  • RHSA-2024:4008
  • RHSA-2024:4486
  • RHSA-2024:3700
  • RHSA-2024:3676
  • RHSA-2024:4159
  • RHSA-2024:10818

Official advisory · high-confidence parse· fetched 1 hour ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • There is no mitigation available for this vulnerability, a package update is required.

Official advisory · high-confidence parse· fetched 1 hour ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.