cbcvebase.
CVE-2022-27649
published 2022-04-04

CVE-2022-27649: A flaw was found in Podman, where containers were started incorrectly with non-empty default permissions. A vulnerability was found in Moby (Docker Engine)…

high7.5CVSS 3.1
AVNACHPRLUINSUCHIHAH
A flaw was found in Podman, where containers were started incorrectly with non-empty default permissions. A vulnerability was found in Moby (Docker Engine), where containers were started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs.

Affected

33 ranges· showing 25
VendorProductVersion rangeFixed in
debianlibpod< libpod 3.4.6+ds1-1 (bookworm)libpod 3.4.6+ds1-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
github.comcontainers_podman_v4>= 0 < 4.0.34.0.3
libpod_projectlibpod>= 0 < 3.0.1+dfsg1-3+deb11u23.0.1+dfsg1-3+deb11u2
libpod_projectlibpod>= 0 < 3.4.6+ds1-13.4.6+ds1-1
msrccbl2_cri-o_1.21.7-3_on_cbl_mariner_2.0
msrccbl2_podman_4.1.1-1_on_cbl_mariner_2.0
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
podman_projectpodman< 4.0.34.0.3
podman_projectpodman
redhatdeveloper_tools
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_for_ibm_z_systems
redhatenterprise_linux_for_ibm_z_systems
redhatenterprise_linux_for_ibm_z_systems_eus
redhatenterprise_linux_for_ibm_z_systems_eus
redhatenterprise_linux_for_power_little_endian
redhatenterprise_linux_for_power_little_endian_eus
redhatenterprise_linux_server_aus

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.5HIGH