CVE-2023-6476 is a high-severity flaw in CRI-O, affecting Red Hat Enterprise Linux and OpenShift Container Platform, where an experimental annotation allows containers to bypass Kubernetes scheduler resource limits. This can lead to a denial of service on the node by enabling pods to consume excessive memory or CPU. The vulnerability has a CVSS score of 7.5, indicating a network-exploitable attack with low complexity and high impact on availability. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.11CPE matchmatch criteria | cpe:2.3:a:redhat:openshift_container_platform:3.11:*:*:*:*:*:*:* | ||
4.13CPE matchmatch criteria | cpe:2.3:a:redhat:openshift_container_platform:4.13:*:*:*:*:*:*:* | ||
4.14CPE matchmatch criteria | cpe:2.3:a:redhat:openshift_container_platform:4.14:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CRI-O's pods can break out of resource confinement on cgroupv2
Jan 10, 2024cri-o: Pods are able to break out of resource confinement on cgroupv2
Jan 9, 2024Cri-o: pods are able to break out of resource confinement on cgroupv2
Jan 9, 2024