CVE-2024-3154High· 7.2▾ TwilightA flaw was found in cri-o, where an arbitrary systemd property can be injected via a Pod annotation. Any user who can create a pod with an arbitrary annotation may perform an arbitrary action on the host system.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.6 · likelihood 0.3 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 24.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
1.4%
A flaw was found in cri-o, where an arbitrary systemd property can be injected via a Pod annotation. Any user who can create a pod with an arbitrary annotation may perform an arbitrary action on the host system.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
github.com/cri-o/cri-o >= 1.29.0, < 1.29.4github.com/cri-o/cri-o >= 1.28.0, < 1.28.6github.com/cri-o/cri-o < 1.27.6Patched in:
github.com/cri-o/cri-o 1.29.4github.com/cri-o/cri-o 1.28.6github.com/cri-o/cri-o 1.27.6Connected by shared product, vendor, weakness, or advisory.
CVE-2024-5154High· 8.1malicious container creates symlink "mtab" on the host External
CVE-2022-1708High· 7.5Node DOS by way of memory exhaustion through ExecSync request in CRI-O
CVE-2022-0811High· 8.8Code Injection in CRI-O
CVE-2022-27652Medium· 4.8Incorrect Default Permissions in CRI-O
CVE-2025-13799Medium· 6.3A vulnerability has been found in ADSLR NBR1005GPEV2 250814-r037c
CVE-2025-13797Medium· 6.3A vulnerability was detected in ADSLR B-QE2W401 250814-r037c