CVE-2022-27649: High severity Podman Project Podman vulnerability
A bug was found in Moby (Docker Engine) where containers were incorrectly started with non-empty inheritable Linux process capabilities, creating an atypical Linux environment and enabling programs with inheritable file capabilities to elevate those capabilities to the permitted set during execve(2). Normally, when executable programs have specified permitted file capabilities, otherwise unprivileged users and processes can execute those programs and gain the specified file capabilities up to the bounding set. Due to this bug, containers which included executable programs with inheritable file capabilities allowed otherwise unprivileged users and processes to additionally gain these inheritable file capabilities up to the container's bounding set. Containers which use Linux users and groups to perform privilege separation inside the container are most directly impacted.
Other sources
A flaw was found in Podman where containers were started incorrectly with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers were started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs.
— Microsoft
A flaw was found in Podman, where containers were started incorrectly with non-empty default permissions. A vulnerability was found in Moby (Docker Engine), where containers were started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs.
Affected Software
Remediation
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID for this flaw in Podman?
The vulnerability ID for this flaw in Podman is CVE-2022-27649.
What is the severity of CVE-2022-27649?
The severity of CVE-2022-27649 is high with a CVSS score of 7.5.
Which software packages are affected by CVE-2022-27649?
The software packages affected by CVE-2022-27649 include Podman 4.0.3, Moby (Docker Engine), Redhat Developer Tools, Redhat Openshift Container Platform, and Redhat Enterprise Linux.
How can I fix CVE-2022-27649?
To fix CVE-2022-27649, upgrade to Podman version 4.0.3 or install the necessary updates from Redhat.
Where can I find more information about CVE-2022-27649?
You can find more information about CVE-2022-27649 in the Redhat Bugzilla and Redhat Advisory links provided.