CVE-2023-6476: Red Hat Openshift Container Platform

High severity, CVSS 7.5. EPSS: 0.9% chance of exploitation in the next 30 days.

A flaw was found in CRI-O that involves an experimental annotation leading to a container being unconfined. This may allow a pod to specify and get any amount of memory/cpu, circumventing the kubernetes scheduler and potentially resulting in a denial of service in the node.

Affected products

  • Red Hat Openshift Container Platform: version 3.11 only; version 4.13 only; version 4.14 only

Published 2024-01-09. Last modified 2026-06-17.