important · Privilege escalation
A pod creator can make CRI-O restore a checkpoint with privileges forbidden by the destination pod policy.
Affects
CRI-O, a Linux container runtime used by Kubernetes and OpenShift nodes.
Where checkpoint restore and CRIU are enabled, saved credentials, capabilities, no_new_privs and seccomp state can replace the requested securityContext. The restored process can therefore start as root with full capabilities and no seccomp. A fix is announced, but pre-fix checkpoint images remain accepted.