CVE-2024-8676
Description
A vulnerability was found in CRI-O, where it can be requested to take a checkpoint archive of a container and later be asked to restore it. When it does that restoration, it attempts to restore the mounts from the restore archive instead of the pod request. As a result, the validations run on the pod spec, verifying that the pod has access to the mounts it specifies are not applicable to a restored container. This flaw allows a malicious user to trick CRI-O into restoring a pod that doesn't have access to host mounts. The user needs access to the kubelet or cri-o socket to call the restore endpoint and trigger the restore.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/cri-o/cri-oGo | < 1.29.11 | 1.29.11 |
github.com/cri-o/cri-oGo | >= 1.30.0, < 1.30.8 | 1.30.8 |
github.com/cri-o/cri-oGo | >= 1.31.0, < 1.31.3 | 1.31.3 |
Affected products
3- ghsa-coords2 versions
< 1.29.11+ 1 more
- (no CPE)range: < 1.29.11
- (no CPE)range: < 0.0.20241209T183251-1.1
Patches
Vulnerability mechanics
References
12- github.com/advisories/GHSA-7p9f-6x8j-gxxpghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-8676ghsaADVISORY
- access.redhat.com/errata/RHBA-2024:10826nvdWEB
- access.redhat.com/errata/RHSA-2025:0648nvdWEB
- access.redhat.com/errata/RHSA-2025:1908nvdWEB
- access.redhat.com/errata/RHSA-2025:3297nvdWEB
- access.redhat.com/errata/RHSA-2025:4211nvdWEB
- access.redhat.com/errata/RHSA-2025:9765nvdWEB
- access.redhat.com/security/cve/CVE-2024-8676nvdWEB
- bugzilla.redhat.com/show_bug.cginvdWEB
- github.com/cri-o/cri-o/commit/e8e7dcb7838d11b5157976bf3e31a5840bb77de7ghsaWEB
- github.com/cri-o/cri-o/security/advisories/GHSA-7p9f-6x8j-gxxpghsaWEB
News mentions
0No linked articles in our index yet.