An update for cri-o is now available for openEuler-22.03-LTS-SP1 Security Advisory openeuler-security@openeuler.org openEuler security committee openEuler-SA-2024-1251 Final 1.0 1.0 2024-03-08 Initial 2024-03-08 2024-03-08 openEuler SA Tool V1.0 2024-03-08 cri-o security update An update for cri-o is now available for openEuler-22.03-LTS-SP1. Open Container Initiative-based implementation of Kubernetes Container Runtime Interface. Security Fix(es): Incorrect handling of the supplementary groups in the CRI-O container engine might lead to sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to set access permissions and is able to execute a binary code in that container.(CVE-2022-2995) An update for cri-o is now available for openEuler-22.03-LTS-SP1. openEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section. High cri-o https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2024-1251 https://www.openeuler.org/en/security/cve/detail.html?id=CVE-2022-2995 https://nvd.nist.gov/vuln/detail/CVE-2022-2995 openEuler-22.03-LTS-SP1 cri-o-1.23.2-2.oe2203sp1.aarch64.rpm cri-o-debuginfo-1.23.2-2.oe2203sp1.aarch64.rpm cri-o-debugsource-1.23.2-2.oe2203sp1.aarch64.rpm cri-o-1.23.2-2.oe2203sp1.src.rpm cri-o-1.23.2-2.oe2203sp1.x86_64.rpm cri-o-debuginfo-1.23.2-2.oe2203sp1.x86_64.rpm cri-o-debugsource-1.23.2-2.oe2203sp1.x86_64.rpm Incorrect handling of the supplementary groups in the CRI-O container engine might lead to sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to set access permissions and is able to execute a binary code in that container. 2024-03-08 CVE-2022-2995 openEuler-22.03-LTS-SP1 High 7.1 AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N cri-o security update 2024-03-08 https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2024-1251