CRI-O applies pod-specified sysctls through its pinns helper. In vulnerable versions pinns does not validate the value, and a + inside the value of an otherwise allowed sysctl is treated as a separator that injects a second, arbitrary sysctl. Smuggling in a kernel.core_pattern=|... pipe handler through that injection sets a core-dump handler on the node; a subsequent core dump then runs attacker code on the host, bypassing the allowed-sysctl list.
# The + injects an extra, unvalidated sysctl into the pinns invocation; the smuggled
# kernel.core_pattern pipe handler runs on the node when any process dumps core.
securityContext:
sysctls:
- name: "kernel.shm_rmid_forced"
value: "1+kernel.core_pattern=|/var/lib/stage"
Exploitation notes#
- The entry requirement is the right to create a pod with sysctls, and a vulnerable CRI-O or pinns; patched versions reject the injected value.
- The injected handler uses the core_pattern mechanism on the node, so the payload runs in the host context on the next core dump.
- The pod-creation foothold itself is often reached through Pod creation to node.