在 CRI-O 中发现了一个与容器检查点(checkpoint)和恢复(restore)功能相关的漏洞。当 CRI-O 配置为从检查点存档中恢复容器时,如果对恢复元数据的验证不充分,可能允许具备相应权限的用户在主机文件系统上执行非预期操作。成功利用该漏洞需要启用容器的检查点与恢复功能,而这并非默认配置。此外,攻击者还必须能够触发从不可信的检查点内容中恢复容器。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-94215 | 5.5 MEDIUM | Keycloak-services: keycloak-services: cross-realm client read/write via request-level cach |
| CVE-2026-94213 | 4.9 MEDIUM | Keycloak-services: keycloak-services: authorization services policy evaluation endpoint le |
| CVE-2026-94217 | 3.5 LOW | Keycloak-services: keycloak-services: uma scope merge across resource owners via resource |
| CVE-2026-94218 | 3.1 LOW | Keycloak-services: keycloak-services: 2fa setup enforcement bypass via authentication sess |
No comments yet