---
id: CVE-2024-3154
title: >-
  A flaw was found in cri-o, where an arbitrary systemd property can be injected
  via a Pod annotation
summary: >-
  A flaw was found in cri-o, where an arbitrary systemd property can be injected
  via a Pod annotation. Any user who can create a pod with an arbitrary
  annotation may perform an arbitrary action on the host system.
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-77
published: '2024-04-26'
updated: '2026-08-24'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-3154'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2024:2669'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:2672'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:2784'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:3496'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2024-3154'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2272532'
    label: secalert@redhat.com
  - url: 'https://github.com/cri-o/cri-o/security/advisories/GHSA-2cgq-h8xw-2v5j'
    label: secalert@redhat.com
  - url: 'https://github.com/opencontainers/runc/pull/4217'
    label: secalert@redhat.com
  - url: >-
      https://github.com/opencontainers/runtime-spec/blob/main/features.md#unsafe-annotations-in-configjson
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:2669'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:2672'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:2784'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:3496'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/security/cve/CVE-2024-3154'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2272532'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://github.com/cri-o/cri-o/security/advisories/GHSA-2cgq-h8xw-2v5j'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://github.com/opencontainers/runc/pull/4217'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://github.com/opencontainers/runtime-spec/blob/main/features.md#unsafe-annotations-in-configjson
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2024-3154'
  - url: 'https://github.com/cri-o/cri-o'
tags:
  - nvd
  - osv
  - go
epss: 0.01418
epssPercentile: 0.71632
ingestedAt: '2026-08-24T16:07:20.572Z'
aliases:
  - GHSA-2cgq-h8xw-2v5j
  - GO-2024-2791
ecosystem: go
vendor: cri-o
product: github.com/cri-o/cri-o
affected:
  - 'github.com/cri-o/cri-o >= 1.29.0, < 1.29.4'
  - 'github.com/cri-o/cri-o >= 1.28.0, < 1.28.6'
  - github.com/cri-o/cri-o < 1.27.6
patched:
  - github.com/cri-o/cri-o 1.29.4
  - github.com/cri-o/cri-o 1.28.6
  - github.com/cri-o/cri-o 1.27.6
---

## Overview

A flaw was found in cri-o, where an arbitrary systemd property can be injected via a Pod annotation. Any user who can create a pod with an arbitrary annotation may perform an arbitrary action on the host system.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2024-3154)

Affected packages:

- `github.com/cri-o/cri-o >= 1.29.0, < 1.29.4`
- `github.com/cri-o/cri-o >= 1.28.0, < 1.28.6`
- `github.com/cri-o/cri-o < 1.27.6`

Patched in:

- `github.com/cri-o/cri-o 1.29.4`
- `github.com/cri-o/cri-o 1.28.6`
- `github.com/cri-o/cri-o 1.27.6`

Source: https://osv.dev/vulnerability/GHSA-2cgq-h8xw-2v5j
