Open Container Initiative-based implementation of Kubernetes Container Runtime
Interface.
Update Information:
Update to release v1.33.5 Resolves: rhbz#2333357, rhbz#2375096, rhbz#2398408, rhbz#2398663, rhbz#2399065, rhbz#2399339 Upstream fixes
* Thu Oct 2 2025 Bradley G Smith
[ 1 ] Bug #2333357 - cri-o-1.34.1 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2333357
[ 2 ] Bug #2375096 - CVE-2025-4437 cri-o1.33: Large /etc/passwd file may lead to Denial of Service [fedora-42]
https://bugzilla.redhat.com/show_bug.cgi?id=2375096
[ 3 ] Bug #2398408 - CVE-2025-47910 cri-o1.33: CrossOriginProtection bypass in net/http [fedora-41]
https://bugzilla.redhat.com/show_bug.cgi?id=2398408
[ 4 ] Bug #2398663 - CVE-2025-47910 cri-o1.33: CrossOriginProtection bypass in net/http [fedora-42]
https://bugzilla.redhat.com/show_bug.cgi?id=2398663
[ 5 ] Bug #2399065 - CVE-2025-47906 cri-o1.33: Unexpected paths returned from LookPath in os/exec [fedora-41]
https://bugzilla.redhat.com/show_bug.cgi?id=2399065
[ 6 ] Bug #2399339 - CVE-2025-47906 cri-o1.33: Unexpected paths returned from LookPath in os/exec [fedora-42]
https://bugzilla.redhat.com/show_bug.cgi?id=2399339
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-172ba9078e' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
Get the latest Linux and open source security news straight to your inbox.