Executive brief
A security flaw was found in CRI-O, a key component used to run containers in Kubernetes environments like OpenShift. An attacker with the ability to set environment variables on a container can bypass existing security checks to modify the system's user database file (/etc/passwd). This could allow an attacker to gain unauthorized access, escalate their privileges, or disrupt container operations.
Technical details
A regression in CRI-O exists because the fix for CVE-2022-4318 incorrectly used a Go raw string literal (`\n`) instead of an interpreted string literal ("\n") when checking for newline characters in the HOME environment variable. This causes the validation logic to search for the literal characters '\' and 'n' rather than the actual newline byte (0x0a). An attacker capable of making a CRI CreateContainer request can supply a real newline character in the HOME variable. This unsanitized value is subsequently passed to utils.GeneratePasswd, which uses fmt.Sprintf to construct the container's /etc/passwd file, enabling arbitrary line injection and potential privilege escalation.
Affected products
- CRI-O CRI-O All versions since December 14, 2022
- Red Hat Red Hat OpenShift Container Platform 4
- Red Hat Confidential Compute Attestation
Timeline
- 2026-07-15: disclosed: Vulnerability reported and recorded in NVD and Red Hat Bugzilla.
- 2022-12-14: other: The original incorrect fix was introduced into the codebase.