-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from CRI-O's handling of ExecSync output. The commit fixes include: (1) Adding a max size cap when reading the log file (replacing ioutil.ReadFile with TruncateAndReadFile in runtime_oci.go), and (2) Introducing LimitWriter to constrain buffer growth in runtime_vm.go. The original functions lacked these safeguards, making them directly vulnerable to resource exhaustion. The patch explicitly addresses these points, confirming the vulnerability's root cause.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| github.com/cri-o/cri-o | go | = 1.24.0 | 1.24.1 |
| github.com/cri-o/cri-o | go | >= 1.23.0, < 1.23.3 | 1.23.3 |
| github.com/cri-o/cri-o | go | < 1.22.5 | 1.22.5 |
Disclosed by Ada Logics in a security audit sponsored by CNCF and facilitated by OSTIF.
Ongoing coverage of React2Shell