Severity
5.9MEDIUM
EPSS
0.1%
top 73.23%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 24
Latest updateAug 21

Description

Moby is an open-source project created by Docker to enable and accelerate software containerization. A bug was found in Moby (Docker Engine) prior to version 20.10.14 where containers were incorrectly started with non-empty inheritable Linux process capabilities, creating an atypical Linux environment and enabling programs with inheritable file capabilities to elevate those capabilities to the permitted set during `execve(2)`. Normally, when executable programs have specified permitted file capa

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:LExploitability: 2.5 | Impact: 3.4

Affected Packages6 packages

NVDmobyproject/moby< 20.10.14
Debiancontainerd< 1.4.13~ds1-1~deb11u2+3
CVEListV5moby/moby< 20.10.14
Gogithub.com/moby/moby< 20.10.14+1

Also affects: Debian Linux 11.0, Fedora 34, 35, 36

Patches

🔴Vulnerability Details

6
OSV
Moby (Docker Engine) started with non-empty inheritable Linux process capabilities in github.com/docker/docker2024-08-21
OSV
Moby (Docker Engine) started with non-empty inheritable Linux process capabilities2024-04-22
GHSA
Moby (Docker Engine) started with non-empty inheritable Linux process capabilities2024-04-22
OSV
containerd vulnerabilities2022-12-13
CVEList
Default inheritable capabilities for linux container should be empty2022-03-24

📋Vendor Advisories

4
Ubuntu
containerd vulnerabilities2022-12-13
Red Hat
moby: Default inheritable capabilities for linux container should be empty2022-03-23
Microsoft
Default inheritable capabilities for linux container should be empty2022-03-08
Debian
CVE-2022-24769: containerd - Moby is an open-source project created by Docker to enable and accelerate softwa...2022
CVE-2022-24769 (MEDIUM CVSS 5.9) | Moby is an open-source project crea | cvebase.io