CRI-O是CRI-O组织开源的一款用于Kubernetes系统的轻量级容器运行时环境。 CRI-O存在输出处理不当漏洞,该漏洞源于针对先前漏洞CVE-2022-4318的修复不正确,导致其被绕过。攻击者能够设置容器上的环境变量,向HOME环境变量注入换行符,通过使用特制的环境变量向/etc/passwd添加任意行。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Confidential Compute Attestation | any |
affected |
| Red Hat | Red Hat OpenShift Container Platform 4 | any |
affected |
any |
affected | ||
| Red Hat | Red Hat OpenShift Container Platform 4.12 | 0:1.25.5-36.rhaos4.12.git2e7f657.el8< * |
unaffected |
| Red Hat | Red Hat OpenShift Container Platform 4.13 | 0:1.26.5-32.rhaos4.13.git1088e36.el8< * |
unaffected |
| Red Hat | Red Hat OpenShift Container Platform 4.16 | 0:1.29.13-14.rhaos4.16.git84cfdc6.el8< * |
unaffected |
| Red Hat | Red Hat OpenShift Container Platform 4.18 | 0:1.31.13-14.rhaos4.18.gitf2de9ac.el8< * |
unaffected |
| Red Hat | Red Hat OpenShift Container Platform 4.19 | 0:1.32.13-11.rhaos4.19.git089e95c.el9< * |
unaffected |
| Red Hat | Red Hat OpenShift Container Platform 4.20 | 0:1.33.13-5.rhaos4.20.git7ebc848.el9< * |
unaffected |
| Red Hat | Red Hat OpenShift Container Platform 4.21 | 0:1.34.11-4.rhaos4.21.git358c4b4.el9< * |
unaffected |
| Red Hat | Red Hat OpenShift Container Platform 4.22 | 0:1.35.6-5.rhaos4.22.git41f610b.el9< * |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat OpenShift Container Platform 4.12 | 0:1.25.5-36.rhaos4.12.git2e7f657.el8 ~ * |
cpe:/a:redhat:openshift:4.12::el8
|
|
| Red Hat | Red Hat OpenShift Container Platform 4.13 | 0:1.26.5-32.rhaos4.13.git1088e36.el8 ~ * |
cpe:/a:redhat:openshift:4.13::el8
|
|
| Red Hat | Red Hat OpenShift Container Platform 4.16 | 0:1.29.13-14.rhaos4.16.git84cfdc6.el8 ~ * |
cpe:/a:redhat:openshift:4.16::el8
|
|
| Red Hat | Red Hat OpenShift Container Platform 4.18 | 0:1.31.13-14.rhaos4.18.gitf2de9ac.el8 ~ * |
cpe:/a:redhat:openshift:4.18::el8
|
|
| Red Hat | Red Hat OpenShift Container Platform 4.19 | 0:1.32.13-11.rhaos4.19.git089e95c.el9 ~ * |
cpe:/a:redhat:openshift:4.19::el9
|
|
| Red Hat | Red Hat OpenShift Container Platform 4.20 | 0:1.33.13-5.rhaos4.20.git7ebc848.el9 ~ * |
cpe:/a:redhat:openshift:4.20::el8
|
|
| Red Hat | Red Hat OpenShift Container Platform 4.21 | 0:1.34.11-4.rhaos4.21.git358c4b4.el9 ~ * |
cpe:/a:redhat:openshift:4.21::el9
|
|
| Red Hat | Red Hat OpenShift Container Platform 4.22 | 0:1.35.6-5.rhaos4.22.git41f610b.el9 ~ * |
cpe:/a:redhat:openshift:4.22::el8
|
|
| Red Hat | Confidential Compute Attestation | - |
cpe:/a:redhat:confidential_compute_attestation:1
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-12382 | 8.2 HIGH | Aap-gateway: missing requestheaderstoremove allows mtls bypass via subject header spoofing |
| CVE-2026-14251 | 7.7 HIGH | Gitops-operator: gitops-operator: missing allowednamespace check in reconcilerhook for clu |
| CVE-2026-15779 | 6.1 MEDIUM | Samba-winbind: samba: pam_winbind mkhomedir chowns critical system paths without validatio |
No comments yet