{"id":"CVE-2022-0811","aliases":["GHSA-6x2m-w449-qwx7","GO-2022-0354"],"url":"https://o3.security/vulnerability/CVE-2022-0811","summary":"Code Injection in CRI-O","details":"A flaw was found in CRI-O in the way it set kernel options for a pod. This issue allows anyone with rights to deploy a pod on a Kubernetes cluster that uses the CRI-O runtime to achieve a container escape and arbitrary code execution as root on the cluster node, where the malicious pod was deployed.","published":"2022-03-16T14:03:40Z","modified":"2026-08-12T03:51:17.870815583Z","cvss":{"score":8.8,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":2,"affectedPackages":[{"ecosystem":"Go","name":"github.com/cri-o/cri-o","fixedVersion":"1.19.6"},{"ecosystem":"Go","name":"github.com/cri-o/cri-o","fixedVersion":"1.20.7"},{"ecosystem":"Go","name":"github.com/cri-o/cri-o","fixedVersion":"1.21.6"},{"ecosystem":"Go","name":"github.com/cri-o/cri-o","fixedVersion":"1.22.3"},{"ecosystem":"Go","name":"github.com/cri-o/cri-o","fixedVersion":"1.23.2"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/0xxx/CVE-2022-0811.json"},{"type":"ADVISORY","url":"https://github.com/cri-o/cri-o/security/advisories/GHSA-6x2m-w449-qwx7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-0811"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2059475"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:17.870815583Z"}}