CRI-O是CRI-O组织开源的一款用于Kubernetes系统的轻量级容器运行时环境。 CRI-O存在输出处理不当漏洞,该漏洞源于针对先前漏洞CVE-2022-4318的修复不正确,导致其被绕过。攻击者能够设置容器上的环境变量,向HOME环境变量注入换行符,通过使用特制的环境变量向/etc/passwd添加任意行。
| 厂商 | 产品 | 版本范围 | 状态 |
|---|---|---|---|
| Red Hat | Confidential Compute Attestation | 全部 |
affected |
| Red Hat | Red Hat OpenShift Container Platform 4 | 全部 |
affected |
全部 |
affected | ||
| Red Hat | Red Hat OpenShift Container Platform 4.12 | 0:1.25.5-36.rhaos4.12.git2e7f657.el8< * |
unaffected |
| Red Hat | Red Hat OpenShift Container Platform 4.13 | 0:1.26.5-32.rhaos4.13.git1088e36.el8< * |
unaffected |
| Red Hat | Red Hat OpenShift Container Platform 4.16 | 0:1.29.13-14.rhaos4.16.git84cfdc6.el8< * |
unaffected |
| Red Hat | Red Hat OpenShift Container Platform 4.18 | 0:1.31.13-14.rhaos4.18.gitf2de9ac.el8< * |
unaffected |
| Red Hat | Red Hat OpenShift Container Platform 4.19 | 0:1.32.13-11.rhaos4.19.git089e95c.el9< * |
unaffected |
| Red Hat | Red Hat OpenShift Container Platform 4.20 | 0:1.33.13-5.rhaos4.20.git7ebc848.el9< * |
unaffected |
| Red Hat | Red Hat OpenShift Container Platform 4.21 | 0:1.34.11-4.rhaos4.21.git358c4b4.el9< * |
unaffected |
| Red Hat | Red Hat OpenShift Container Platform 4.22 | 0:1.35.6-5.rhaos4.22.git41f610b.el9< * |
unaffected |
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| 厂商 | 产品 | 影响版本 | CPE | 订阅 |
|---|---|---|---|---|
| Red Hat | Red Hat OpenShift Container Platform 4.12 | 0:1.25.5-36.rhaos4.12.git2e7f657.el8 ~ * |
cpe:/a:redhat:openshift:4.12::el8
|
|
| Red Hat | Red Hat OpenShift Container Platform 4.13 | 0:1.26.5-32.rhaos4.13.git1088e36.el8 ~ * |
cpe:/a:redhat:openshift:4.13::el8
|
|
| Red Hat | Red Hat OpenShift Container Platform 4.16 | 0:1.29.13-14.rhaos4.16.git84cfdc6.el8 ~ * |
cpe:/a:redhat:openshift:4.16::el8
|
|
| Red Hat | Red Hat OpenShift Container Platform 4.18 | 0:1.31.13-14.rhaos4.18.gitf2de9ac.el8 ~ * |
cpe:/a:redhat:openshift:4.18::el8
|
|
| Red Hat | Red Hat OpenShift Container Platform 4.19 | 0:1.32.13-11.rhaos4.19.git089e95c.el9 ~ * |
cpe:/a:redhat:openshift:4.19::el9
|
|
| Red Hat | Red Hat OpenShift Container Platform 4.20 | 0:1.33.13-5.rhaos4.20.git7ebc848.el9 ~ * |
cpe:/a:redhat:openshift:4.20::el8
|
|
| Red Hat | Red Hat OpenShift Container Platform 4.21 | 0:1.34.11-4.rhaos4.21.git358c4b4.el9 ~ * |
cpe:/a:redhat:openshift:4.21::el9
|
|
| Red Hat | Red Hat OpenShift Container Platform 4.22 | 0:1.35.6-5.rhaos4.22.git41f610b.el9 ~ * |
cpe:/a:redhat:openshift:4.22::el8
|
|
| Red Hat | Confidential Compute Attestation | - |
cpe:/a:redhat:confidential_compute_attestation:1
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| # | POC 描述 | 源链接 | 神龙链接 |
|---|
| CVE-2026-12382 | 8.2 HIGH | Red Hat Ansible Automation Platform 授权问题漏洞 |
| CVE-2026-14251 | 7.7 HIGH | Red Hat OpenShift GitOps 授权问题漏洞 |
| CVE-2026-15779 | 6.1 MEDIUM | Samba 权限许可和访问控制问题漏洞 |
暂无评论