CVE-2024-5154

A flaw was found in cri-o. A malicious container can create a symbolic link to arbitrary files on the host via directory traversal (“../“). This flaw allows the container to read and write to arbitrary files on the host system.

Credits

Red Hat would like to thank Erik Sjölund (erik.sjolund@gmail.com) for reporting this issue.

References