<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 00:55:22 +0000</lastBuildDate>
    <item>
      <title>bdu:2022-01319</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-01319</link>
      <description>bdu:2022-01319</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-01319</guid>
    </item>
    <item>
      <title>EUVD-2026-11244</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-11244</link>
      <description>EUVD-2026-11244</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-11244</guid>
    </item>
    <item>
      <title>fkie_cve-2022-0811</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-0811</link>
      <description>&lt;p&gt;A flaw was found in CRI-O in the way it set kernel options for a pod. This issue allows anyone with rights to deploy a pod on a Kubernetes cluster that uses the CRI-O runtime to achieve a container escape and arbitrary code execution as root on the cluster node, where the malicious pod was deployed.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in CRI-O in the way it set kernel options for a pod. This issue allows anyone with rights to deploy a pod on a Kubernetes cluster that uses the CRI-O runtime to achieve a container escape and arbitrary code execution as root on the cluster node, where the malicious pod was deployed.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-0811</guid>
    </item>
    <item>
      <title>GHSA-6x2m-w449-qwx7 — Code Injection in CRI-O</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6x2m-w449-qwx7</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/cri-o/cri-o&lt;/p&gt;
&lt;p&gt;### Impact
A flaw introduced in CRI-O version 1.19 which an attacker can use to bypass the safeguards and set arbitrary kernel parameters on the host. As a result, anyone with rights to deploy a pod on a Kubernetes cluster that uses the CRI-O runtime can abuse the `kernel.core_pattern` kernel parameter to achieve container escape and arbitrary code execution as root on any node in the cluster.&lt;/p&gt;
&lt;p&gt;### Patches
The patches will be present in 1.19.6, 1.20.7, 1.21.6, 1.22.3, 1.23.2, 1.24.0&lt;/p&gt;
&lt;p&gt;### Workarounds
- Users can set manage_ns_lifecycle to false, which causes the sysctls to be configured by the OCI runtime, which typically filter these cases. This option is available in 1.20 and 1.19. Newer versions don&amp;#39;t have this option.
- An admission webhook could be created to deny pods that specify a `+` in the sysctl value of a pod.
- A [PodSecurityPolicy](https://kubernetes.io/docs/tasks/administer-cluster/sysctl-cluster/#podsecuritypolicy) [deprecated] could be created, specifying all sysctls as forbidden like so: 
```
apiVersion: policy/v1beta1
kind: PodSecurityPolicy
metadata:
  name: sysctl-psp
spec:
  forbiddenSysctls:
    - &amp;#34;*&amp;#34;
```
However, this option will not work if any sysctls are required by any pods in the cluster.&lt;/p&gt;
&lt;p&gt;### Credits
Credit for finding this vulnerability goes to John Walker and Manoj Ahuje of Crowdstrike. The CRI-O community deeply thanks them for the report.&lt;/p&gt;
&lt;p&gt;### For more information
If you have any questions or comments about this advisory:
* Open an issue in…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/cri-o/cri-o&lt;/p&gt;
&lt;p&gt;### Impact
A flaw introduced in CRI-O version 1.19 which an attacker can use to bypass the safeguards and set arbitrary kernel parameters on the host. As a result, anyone with rights to deploy a pod on a Kubernetes cluster that uses the CRI-O runtime can abuse the `kernel.core_pattern` kernel parameter to achieve container escape and arbitrary code execution as root on any node in the cluster.&lt;/p&gt;
&lt;p&gt;### Patches
The patches will be present in 1.19.6, 1.20.7, 1.21.6, 1.22.3, 1.23.2, 1.24.0&lt;/p&gt;
&lt;p&gt;### Workarounds
- Users can set manage_ns_lifecycle to false, which causes the sysctls to be configured by the OCI runtime, which typically filter these cases. This option is available in 1.20 and 1.19. Newer versions don&amp;#39;t have this option.
- An admission webhook could be created to deny pods that specify a `+` in the sysctl value of a pod.
- A [PodSecurityPolicy](https://kubernetes.io/docs/tasks/administer-cluster/sysctl-cluster/#podsecuritypolicy) [deprecated] could be created, specifying all sysctls as forbidden like so: 
```
apiVersion: policy/v1beta1
kind: PodSecurityPolicy
metadata:
  name: sysctl-psp
spec:
  forbiddenSysctls:
    - &amp;#34;*&amp;#34;
```
However, this option will not work if any sysctls are required by any pods in the cluster.&lt;/p&gt;
&lt;p&gt;### Credits
Credit for finding this vulnerability goes to John Walker and Manoj Ahuje of Crowdstrike. The CRI-O community deeply thanks them for the report.&lt;/p&gt;
&lt;p&gt;### For more information
If you have any questions or comments about this advisory:
* Open an issue in…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6x2m-w449-qwx7</guid>
    </item>
    <item>
      <title>gsd-2022-0811</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-0811</link>
      <description>gsd-2022-0811</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-0811</guid>
    </item>
    <item>
      <title>msrc_CVE-2022-0811 — A flaw was found in CRI-O in the way it set kernel options for a pod. This issue allows anyone with rights to deploy a…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2022-0811</link>
      <description>msrc_CVE-2022-0811</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2022-0811</guid>
    </item>
    <item>
      <title>RHSA-2022:0810 — Red Hat Security Advisory: OpenShift Container Platform 4.10.4 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2022:0810</link>
      <description>&lt;p&gt;CRI-O: Arbitrary code execution in cri-o via abusing “kernel.core_pattern” kernel parameter&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;CRI-O: Arbitrary code execution in cri-o via abusing “kernel.core_pattern” kernel parameter&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2022:0810</guid>
    </item>
  </channel>
</rss>
