Database/Container, Kubernetes & orchestration
containerd: On SELinux hosts, an unprivileged pod with a hostPath volume can gain full read/write to the host filesystem
CVE-2021-43816Container, Kubernetes & orchestrationcurated
Impact
On SELinux hosts, an unprivileged pod with a hostPath volume can gain full read/write to the host filesystem
Who can reach it
Cluster user able to create a pod with a hostPath volume
What to do
Rolling containerd upgrade with node drain; block hostPath in tenant namespaces
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.