A flaw was found in CRI-O that involves an experimental annotation leading to a container being unconfined. This may allow a pod to specify and get any amount of memory/cpu, circumventing the kubernetes scheduler and potentially resulting in a denial of service in the node.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| github.com/cri-o/cri-o(Go) | 1.29.0 | 1.29.1 | N/A |
| github.com/cri-o/cri-o(Go) | 1.28.0 | 1.28.3 | N/A |
| github.com/cri-o/cri-o(Go) | 0 | 1.27.3 | N/A |
CVSS Metrics