First published: Tue Mar 22 2022(Updated: )
A flaw was found in Podman, where containers were started incorrectly with non-empty default permissions. A vulnerability was found in Moby (Docker Engine), where containers were started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Podman Project Podman | <4.0.3 | |
Redhat Developer Tools | =1.0 | |
Redhat Openshift Container Platform | =4.0 | |
Redhat Enterprise Linux | =8.0 | |
Redhat Enterprise Linux | =8.6 | |
Redhat Enterprise Linux Eus | =8.4 | |
Redhat Enterprise Linux Eus | =8.6 | |
Redhat Enterprise Linux For Ibm Z Systems | =8.0 | |
Redhat Enterprise Linux For Ibm Z Systems | =8.6 | |
Redhat Enterprise Linux For Ibm Z Systems Eus | =8.4 | |
Redhat Enterprise Linux For Ibm Z Systems Eus | =8.6 | |
Redhat Enterprise Linux For Power Little Endian | =8.0 | |
Redhat Enterprise Linux For Power Little Endian Eus | =8.4 | |
Redhat Enterprise Linux Server Aus | =8.4 | |
Redhat Enterprise Linux Server Aus | =8.6 | |
Redhat Enterprise Linux Server For Power Little Endian Update Services For Sap Solutions | =8.4 | |
Redhat Enterprise Linux Server For Power Little Endian Update Services For Sap Solutions | =8.6 | |
Redhat Enterprise Linux Server Tus | =8.4 | |
Redhat Enterprise Linux Server Tus | =8.6 | |
Redhat Enterprise Linux Server Update Services For Sap Solutions | =8.4 | |
Redhat Enterprise Linux Server Update Services For Sap Solutions | =8.6 | |
Fedoraproject Fedora | =34 | |
Fedoraproject Fedora | =35 | |
Fedoraproject Fedora | =36 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
The vulnerability ID for this flaw in Podman is CVE-2022-27649.
The severity of CVE-2022-27649 is high with a CVSS score of 7.5.
The software packages affected by CVE-2022-27649 include Podman 4.0.3, Moby (Docker Engine), Redhat Developer Tools, Redhat Openshift Container Platform, and Redhat Enterprise Linux.
To fix CVE-2022-27649, upgrade to Podman version 4.0.3 or install the necessary updates from Redhat.
You can find more information about CVE-2022-27649 in the Redhat Bugzilla and Redhat Advisory links provided.