Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-1708

23
FAUCET Score

CVE-2022-1708 is a high-severity vulnerability in CRI-O, affecting products like Fedora Project, Kubernetes, and Red Hat. It allows an attacker with Kube API access to exhaust a node's memory or disk space by executing commands in a container that produce large outputs, which CRI-O then reads entirely. This can lead to a denial of service, impacting system availability. The vulnerability has a CVSS score of 7.5 (High) with an attack vector of Network and low attack complexity, requiring no user interaction. Its primary impact is on availability (A:H). Currently, there is no evidence of active exploitation, nor is there publicly available exploit code in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage are minimal, which is typical for the majority of CVEs.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.19.7CPE matchmatch criteria
cpe:2.3:a:kubernetes:cri-o:*:*:*:*:*:*:*:*
>= 1.20.0, < 1.20.8CPE matchmatch criteria
cpe:2.3:a:kubernetes:cri-o:*:*:*:*:*:*:*:*
>= 1.21.0, < 1.21.8CPE matchmatch criteria
cpe:2.3:a:kubernetes:cri-o:*:*:*:*:*:*:*:*
>= 1.22.0, < 1.22.5CPE matchmatch criteria
cpe:2.3:a:kubernetes:cri-o:*:*:*:*:*:*:*:*
>= 1.23.0, < 1.23.3CPE matchmatch criteria
cpe:2.3:a:kubernetes:cri-o:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
2.83%
Probability of exploitation in next 30 days
EPSS Percentile
85.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0283 is in the 73rd percentile among its peer group of 51,551 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (25)

github_advisorypatch availablevia nvd_reference
View patch
gopatch availablevia ghsa
Product: github.com/cri-o/cri-oFixed in: 1.24.1
gopatch availablevia ghsa
Product: github.com/cri-o/cri-oFixed in: 1.23.3
gopatch availablevia ghsa
Product: github.com/cri-o/cri-oFixed in: 1.22.5
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 ARMFixed in: 1.21.7-1
microsoftpatch availablevia msrc
Product: 19490-16823Fixed in: 1.21.7-1
microsoftpatch availablevia msrc
Product: 19777-17086Fixed in: 1.21.7-1
microsoftpatch availablevia msrc
Product: cbl2 cri-o 1.21.7-1 on CBL Mariner 2.0Fixed in: 1.21.7-1
microsoftpatch availablevia msrc
Product: cbl2 cri-o 1.22.3-14 on CBL Mariner 2.0Fixed in: 1.21.7-1
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 x64Fixed in: 1.21.7-1
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.10Fixed in: cri-o-0:1.23.3-3.rhaos4.10.git5fe1720.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.6Fixed in: cri-o-0:1.19.7-2.rhaos4.6.git3c20b65.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.7Fixed in: conmon-2:2.0.29-3.rhaos4.7.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.7Fixed in: cri-o-0:1.20.8-3.rhaos4.7.gitb9df556.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.8Fixed in: conmon-2:2.0.29-3.rhaos4.8.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.8Fixed in: cri-o-0:1.21.8-3.rhaos4.8.gitd7fbb0d.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.9Fixed in: conmon-2:2.0.29-3.rhaos4.9.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.9Fixed in: cri-o-0:1.22.5-3.rhaos4.9.gitb6d3a87.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.6Fixed in: conmon-2:2.0.21-3.rhaos4.6.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: container-tools:rhel8-8070020220929222448.39077419
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: container-tools:4.0-8070020220830101436.39077419
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: container-tools:3.0-8070020220802115906.39077419
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.11Fixed in: cri-o-0:1.11.16-0.17.rhaos3.11.git4c0a8ad.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.10Fixed in: conmon-2:2.0.29-3.rhaos4.10.el8
View patch
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: conmon

Vendor Advisories (4)

microsoft2024-Apr/CVE-2022-1708

CVE-2022-1708

Apr 9, 2024
microsoft2022-Jun/CVE-2022-1708Important

A vulnerability was found in CRI-O that causes memory or disk space exhaustion on the node for anyone with access to the Kube API. The ExecSync request runs commands in a container and logs the output of the command. This output is then read by CRI-O after command execution and it is read in a manner where the entire file corresponding to the output of the command is read in. Thus if the output of the command is large it is possible to exhaust the memory or the disk space of the node when CRI-O reads the output of the command. The highest threat from this vulnerability is system availability.

Jun 14, 2022
goGHSA-fcm2-6c3h-pg6jhigh

Node DOS by way of memory exhaustion through ExecSync request in CRI-O

Jun 6, 2022
redhatCVE-2022-1708Moderate

cri-o: memory exhaustion on the node when access to the kube api

Jun 6, 2022

References

bugzilla.redhat.com / show_bug.cgi
Issue TrackingThird Party Advisory
github.com / cri-o/cri-o/commit/f032cf649ecc7e0c46718bd9e7814bfb317cb544
Patch
github.com / cri-o/cri-o/security/advisories/GHSA-fcm2-6c3h-pg6j
ExploitThird Party Advisory