{"id":"CVE-2022-0532","aliases":["GHSA-jqmc-79gx-7g8p","GO-2022-0608"],"url":"https://o3.security/vulnerability/CVE-2022-0532","summary":"Incorrect Permission Assignment for Critical Resource in CRI-O","details":"An incorrect sysctls validation vulnerability was found in CRI-O 1.18 and earlier. The sysctls from the list of \"safe\" sysctls specified for the cluster will be applied to the host if an attacker is able to create a pod with a hostIPC and hostNetwork kernel namespace.","published":"2022-02-09T22:05:13Z","modified":"2026-08-12T03:51:13.410859697Z","cvss":{"score":4.2,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/cri-o/cri-o","fixedVersion":"1.23.1"}],"fix":null,"references":[{"type":"WEB","url":"https://kubernetes.io/docs/tasks/administer-cluster/sysctl-cluster/#enabling-unsafe-sysctls"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/0xxx/CVE-2022-0532.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-0532"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2051730"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:13.410859697Z"}}