High [CVE-2024-5154] Cri-o: malicious container can create symlink on host
This high-severity Red Hat Linux advisory covers CVE-2024-5154 affecting Red Hat OpenShift Container Platform 4.12, Red Hat OpenShift Container Platform 4.13, Red Hat OpenShift Container Platform 4.14.
Android app · Google Play
Monitor future Red Hat Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
A flaw was found in cri-o. A malicious container can create a symbolic link to arbitrary files on the host via directory traversal (“../“).
This flaw allows the container to read and write to arbitrary files on the host system. Red Hat OpenShift Container Platform (OCP) includes the vulnerable cri-o library, however it does not load untrusted container, therefore impact is reduced to Important.
Red Hat severity: Important — CVSS 8.1 (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N). Weakness: CWE-22.
Affected Red Hat products: Red Hat OpenShift Container Platform 4.12; Red Hat OpenShift Container Platform 4.13; Red Hat OpenShift Container Platform 4.14; Red Hat OpenShift Container Platform 4.15; Red Hat OpenShift Container Platform 4.16; Red Hat OpenShift Container Platform 4.17; Red Hat OpenShift Container Platform 3.11.
Red Hat lists Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9 as not affected. Will not fix / out of support: Red Hat OpenShift Container Platform 3.11.
Red Hat fixing advisory: RHSA-2024:4008, RHSA-2024:4486, RHSA-2024:3700, RHSA-2024:3676, RHSA-2024:4159, RHSA-2024:10818.
Affected versions
No affected-version range was extracted from the source record. The vendor advisory is authoritative — check it before change work.
Official advisory · high-confidence parse· fetched 1 hour ago·verify at source
- cri-o-0:1.25.5-21.2.rhaos4.12.gita3eb75f.el8
- cri-o-0:1.26.5-18.2.rhaos4.13.git2e90133.el8
- cri-o-0:1.27.7-3.rhaos4.14.git674563e.el8
- cri-o-0:1.28.7-2.rhaos4.15.git111aec5.el8
- cri-o-0:1.29.5-7.rhaos4.16.git7db4ada.el8
- kernel-0:5.14.0-427.24.1.el9_4
- openshift-0:4.16.0-202406191607.p0.g58452d8.assembly.stream.el8
- rhcos-417.94.202412040832-0
- RHSA-2024:4008
- RHSA-2024:4486
- RHSA-2024:3700
- RHSA-2024:3676
- RHSA-2024:4159
- RHSA-2024:10818
Official advisory · high-confidence parse· fetched 1 hour ago·verify at source
Mitigation checklist
- There is no mitigation available for this vulnerability, a package update is required.
Official advisory · high-confidence parse· fetched 1 hour ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.