发现 CRI-O 容器创建过程中处理环境变量(具体为 中的 函数,该函数被 中的 调用)存在缺陷。当 请求中提供空的 CRI 字段时,CRI-O 会回退到使用目标 OCI 镜像配置中的 条目,且不进行过滤。而正常合并路径会在使用前验证每个条目是否符合 格式。如果 OCI 镜像的 中包含不含 字符的条目(例如裸字符串 ),CRI-O 会将该条目拆分为只含一个元素的切片,随后尝试访问其第二个元素,导致越界索引。这会触发 守护进程进程中未捕获的 Go 运行时 panic,导致进程崩溃,并使节点上所有工作负载的容器运行时服
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-71366 | 7.7 HIGH | Awx: notification backends allow ssrf and credential leakage |
| CVE-2026-71364 | 7.2 HIGH | Awx: project archive extraction allows path traversal file writes |
| CVE-2026-19685 | 7.1 HIGH | Networkmanager: networkmanager: 802-1x ca-path and phase2-ca-path bypass private_user rest |
| CVE-2026-78367 | 7.0 HIGH | Rpm: rpmbuild gettarspec() crafted tar member name → macro injection |
| CVE-2026-78323 | 6.5 MEDIUM | Jss: jss: jsstrustmanager does not verify nss trust flags on ca certificates |
No comments yet