CVE-2024-5154

Executive Summary

CVE-2024-5154 exposes a flaw in cri‑o that lets a malicious container create symbolic links to arbitrary host files via directory traversal ("../"). This enables the container to read and write any host file, effectively bypassing isolation and allowing privilege escalation, data exfiltration, and full system compromise.


Authoritative CVE Metadata - CVSS Base Score: 8.1 (HIGH) - Published: 2024-06-12T09:15:19.973 - Last Modified: 2026-08-21T12:16:17.343

Original Description: A flaw was found in cri-o. A malicious container can create a symbolic link to arbitrary files on the host via directory traversal (“../“). This flaw allows the container to read and write to arbitrary files on the host system.

"Adversity has the effect of eliciting talents, which in prosperous circumstances would have lain dormant."

— Horace
Source: NVD