CVE-2022-2739: Infoleak
The podman packages version podman-1.6.4-32.el79 as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190 (https://access.redhat.com/errata/RHSA-2022:2190) included an incorrect version of podman that was missing multiple bug and security fixes. One of the fixes regressed in that update was the fix for CVE-2020-14370, that was previously corrected in the podman packages in Red Hat Enterprise Linux 7 Extras via RHSA-2020:5056 (https://access.redhat.com/errata/RHSA-2020:5056). The CVE-2022-2739 was assigned to this security regression and it is specific to the podman packages produced by Red Hat.
The original issue - CVE-2020-14370 - could possibly allow an attacker to gain access to sensitive information stored in environment variables. For more details about the original issue, see:
https://access.redhat.com/security/cve/CVE-2020-14370 https://bugzilla.redhat.com/showbug.cgi?id=CVE-2020-14370
Other sources
The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190 advisory included an incorrect version of podman missing the fix for CVE-2020-14370, which was previously fixed via RHSA-2020:5056. This issue could possibly allow an attacker to gain access to sensitive information stored in environment variables.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-2739?
CVE-2022-2739 is a vulnerability in the version of Podman released for Red Hat Enterprise Linux 7 Extras.
What is the severity of CVE-2022-2739?
The severity of CVE-2022-2739 is medium with a severity value of 5.3.
What software versions are affected by CVE-2022-2739?
Red Hat Enterprise Linux Server 7.0, Red Hat Enterprise Linux Workstation 7.0, and Podman 1.6.4-32.el7_9 are affected by CVE-2022-2739.
Is there a fix available for CVE-2022-2739?
Yes, a fix is available for CVE-2022-2739. Please refer to the official Red Hat advisory for the fix.
Where can I find more information about CVE-2022-2739?
You can find more information about CVE-2022-2739 in the official Red Hat security advisory, Bugzilla entry, and the associated errata.