{"id":"AZL-53540","summary":"CVE-2024-8676 affecting package cri-o 1.30.1-1","details":"A vulnerability was found in CRI-O, where it can be requested to take a checkpoint archive of a container and later be asked to restore it. When it does that restoration, it attempts to restore the mounts from the restore archive instead of the pod request. As a result, the validations run on the pod spec, verifying that the pod has access to the mounts it specifies are not applicable to a restored container. This flaw allows a malicious user to trick CRI-O into restoring a pod that doesn't have access to host mounts. The user needs access to the kubelet or cri-o socket to call the restore endpoint and trigger the restore.","modified":"2026-04-21T04:35:17.103596Z","published":"2024-11-26T20:15:34Z","upstream":["CVE-2024-8676"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-8676"}],"affected":[{"package":{"name":"cri-o","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/cri-o"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"1.30.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-53540.json"}}],"schema_version":"1.7.5"}