blob: f4efac02e7d114bd400280d0a575a0029b7ce8e6 [file] [log] [blame]
id: GO-2024-3292
modules:
- module: github.com/cri-o/cri-o
versions:
- fixed: 1.29.11
- introduced: 1.30.0
- fixed: 1.30.8
- introduced: 1.31.0
- fixed: 1.31.3
vulnerable_at: 1.31.2
summary: 'CRI-O: Maliciously structured checkpoint file can gain arbitrary node access in github.com/cri-o/cri-o'
cves:
- CVE-2024-8676
ghsas:
- GHSA-7p9f-6x8j-gxxp
references:
- advisory: https://github.com/cri-o/cri-o/security/advisories/GHSA-7p9f-6x8j-gxxp
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2024-8676
- fix: https://github.com/cri-o/cri-o/commit/e8e7dcb7838d11b5157976bf3e31a5840bb77de7
- web: https://access.redhat.com/security/cve/CVE-2024-8676
- web: https://bugzilla.redhat.com/show_bug.cgi?id=2313842
source:
id: GHSA-7p9f-6x8j-gxxp
created: 2024-12-04T11:10:38.049589-05:00
review_status: UNREVIEWED