GPU VulnDB

Database/Container, Kubernetes & orchestration

containerd: Crafted image config allows arbitrary host file read by containers launched via the CRI plugin

CVE-2022-23648Container, Kubernetes & orchestrationcurated

Impact

Crafted image config allows arbitrary host file read by containers launched via the CRI plugin

Who can reach it

Malicious image

What to do

Rolling containerd upgrade with node drain

Fleet impact

How widespread

Universal - containerd is the runtime under nearly every Kubernetes-based GPU cloud; affects <1.6.1 / 1.5.10 / 1.4.12

Cost to remediate

daemon-restart - containerd upgrade; with --restart semantics containers may survive, but the fleet-wide rollout still means touching every node

Why it hits the whole fleet

A specially crafted *image config* - i.e. something a customer supplies - mounts read-only copies of arbitrary host files into the container, bypassing Pod Security Policy; any tenant who can push an image reads host secrets on every node they land on

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.