CVE-2019-14891
Summary
| CVE | CVE-2019-14891 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-11-25 11:15:00 UTC |
| Updated | 2020-02-28 18:10:00 UTC |
| Description | A flaw was found in cri-o, as a result of all pod-related processes being placed in the same memory cgroup. This can result in container management (conmon) processes being killed if a workload process triggers an out-of-memory (OOM) condition for the cgroup. An attacker could abuse this flaw to get host network access on an cri-o host. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| 1772280 – (CVE-2019-14891) CVE-2019-14891 cri-o: infra container reparented to systemd following OOM Killer killing it's conmon |
CONFIRM |
bugzilla.redhat.com |
Issue Tracking, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 770033 Red Hat OpenShift Container Platform 4.2.36 Security Update (RHSA-2020:2776)