First published: Wed Oct 12 2022(Updated: )
The following cri-o packages as released for Red Hat OpenShift Container Platform 4.9.48, 4.10.31 and 4.11.6 included an incorrect version of cri-o that was missing the fix for CVE-2022-27652: - cri-o-1.22.5-10.rhaos4.9.gitd14fede.el8 via RHBA-2022:6316 (<a href="https://access.redhat.com/errata/RHBA-2022:6316">https://access.redhat.com/errata/RHBA-2022:6316</a>) - cri-o-1.23.3-16.rhaos4.10.gitd7c9b35.el8 via RHBA-2022:6257 (<a href="https://access.redhat.com/errata/RHBA-2022:6257">https://access.redhat.com/errata/RHBA-2022:6257</a>) - cri-o-1.24.2-7.rhaos4.11.gitca400e0.el8 via RHBA-2022:6658 (<a href="https://access.redhat.com/errata/RHBA-2022:6658">https://access.redhat.com/errata/RHBA-2022:6658</a>) The regressed <a href="https://access.redhat.com/security/cve/CVE-2022-27652">CVE-2022-27652</a> was previously corrected in Red Hat OpenShift Container Platform 4.9.41 and 4.10.12 via RHBA-2022:5433 and RHSA-2022:1600, respectively. <a href="https://access.redhat.com/security/cve/CVE-2022-3466">CVE-2022-3466</a> was assigned to this security regression and it is specific to the cri-o packages produced by Red Hat. The original issue could allow an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs. For more details about the original issue, see: <a href="https://access.redhat.com/security/cve/CVE-2022-27652">https://access.redhat.com/security/cve/CVE-2022-27652</a> <a href="https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2022-27652">https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2022-27652</a>
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat OpenShift Container Platform for IBM LinuxONE | ||
Red Hat cri-o |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-2134063 is considered moderate due to the missing fix for CVE-2022-27652 in specific cri-o packages.
To fix REDHAT-BUG-2134063, update the affected cri-o packages to the versions that include the fix for CVE-2022-27652.
The affected versions of cri-o include 1.22.5-10.rhaos4.9.gitd14fede.el8, as released in Red Hat OpenShift Container Platform 4.9.48, 4.10.31, and 4.11.6.
CVE-2022-27652 is a vulnerability that was not properly fixed in the affected versions of cri-o, leading to potential security risks.
Currently, there are no known workarounds for REDHAT-BUG-2134063 other than applying the necessary updates to the affected packages.