NA

CVE-2023-6476

Published: 09/01/2024 Updated: 04/02/2024
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

A flaw was found in CRI-O that involves an experimental annotation leading to a container being unconfined. This may allow a pod to specify and get any amount of memory/cpu, circumventing the kubernetes scheduler and potentially resulting in a denial of service in the node.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat openshift container platform 3.11

redhat openshift_container_platform 4.13

redhat openshift_container_platform 4.14

Vendor Advisories

Synopsis Important: OpenShift Container Platform 41410 bug fix and security update Type/Severity Security Advisory: Important Topic Red Hat OpenShift Container Platform release 41410 is now available with updates to packages and images that fix several bugs and add enhancementsThis release includes a security update for Red Hat OpenShift ...
Synopsis Moderate: OpenShift Container Platform 41329 packages and security update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for containernetworking-plugins, cri-o, kernel, kernel-rt, and openshift is now ...
Synopsis Moderate: OpenShift Container Platform 4149 packages and security update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic Red Hat OpenShift Container Platform release 4149 is now available with updates to packa ...
Synopsis Moderate: OpenShift Container Platform 4149 bug fix and security update Type/Severity Security Advisory: Moderate Topic Red Hat OpenShift Container Platform release 4149 is now available with updates to packages and images that fix several bugs and add enhancementsThis release includes a security update for Red Hat OpenShift Con ...
Description<!---->A flaw was found in CRI-O that involves an experimental annotation leading to a container being unconfined This may allow a pod to specify and get any amount of memory/cpu, circumventing the kubernetes scheduler and potentially resulting in a denial of service in the nodeA flaw was found in CRI-O that involves an experimental an ...