cri-o has 5 CVEs on record between 2022 and 2024. The median CVSS is 7.5 (high). None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.5
- Publish → KEV
- —
- Last 90 days
- 0 prev 0
Weakness classes
Products
- github.com/cri-o/cri-o 5
5
Total CVEs
0
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
CVE-2022-0811High· 8.8Code Injection in CRI-O64CVE-2024-5154High· 8.1malicious container creates symlink "mtab" on the host External45CVE-2022-1708High· 7.5Node DOS by way of memory exhaustion through ExecSync request in CRI-O42CVE-2024-3154High· 7.2A flaw was found in cri-o, where an arbitrary systemd property can be injected via a Pod annotation40CVE-2022-27652Medium· 4.8Incorrect Default Permissions in CRI-O26
cri-o vulnerabilities
CVEs affecting cri-o, newest first. Open any entry for full detail, references, and exploit status.
5 CVEsRSS
CVE-2024-5154High· 8.1malicious container creates symlink "mtab" on the host External
malicious container creates symlink "mtab" on the host External
▾ Twilightcri-o · github.com/cri-o/cri-oEPSS 1.2%via OSV
CVE-2024-3154High· 7.2A flaw was found in cri-o, where an arbitrary systemd property can be injected via a Pod annotation
A flaw was found in cri-o, where an arbitrary systemd property can be injected via a Pod annotation. Any user who can create a pod with an arbitrary annotation may perform an arbitrary action on the host system.
▾ Twilightcri-o · github.com/cri-o/cri-oEPSS 1.4%via NVD
CVE-2022-1708High· 7.5Node DOS by way of memory exhaustion through ExecSync request in CRI-O
Node DOS by way of memory exhaustion through ExecSync request in CRI-O
▾ Twilightcri-o · github.com/cri-o/cri-oEPSS 3.1%via OSV
CVE-2022-27652Medium· 4.8Incorrect Default Permissions in CRI-O
Incorrect Default Permissions in CRI-O
▾ Sunlitcri-o · github.com/cri-o/cri-oEPSS 0.25%via OSV
CVE-2022-0811High· 8.8PoCCode Injection in CRI-O
Code Injection in CRI-O
▾ Midnightcri-o · github.com/cri-o/cri-oEPSS 19%via OSV