Impact
A vulnerability exists in CRI‑O's checkpoint‑and‑restore feature, where insufficient validation of restore metadata allows a privileged user to perform unintended operations on the host filesystem. The flaw can enable unauthorized reading, modification, or deletion of host files, effectively granting the attacker control over the host. The attack requires the feature to be enabled and a container to be restored from untrusted checkpoint content.
Affected Systems
The affected product is Red Hat OpenShift Container Platform 4, which includes the CRI‑O runtime. Any installation that has checkpoint‑and‑restore enabled is susceptible. No specific component versions are listed beyond the platform suite.
Risk and Exploitability
The CVSS score of 8.0 classifies the vulnerability as high severity, and the EPSS score is not available, indicating no known exploitation probability in the data set. The vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed, widely disseminated exploitation. The likely attack vector is an attacker with sufficient privileges to trigger the restore of a container from an untrusted checkpoint, which is not the default configuration.
OpenCVE Enrichment