CVE-2022-27649

Severity
7.5HIGH
EPSS
0.5%
top 32.37%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 4
Latest updateAug 21

Description

A flaw was found in Podman, where containers were started incorrectly with non-empty default permissions. A vulnerability was found in Moby (Docker Engine), where containers were started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.6 | Impact: 5.9

Affected Packages5 packages

CVEListV5podmanAffects all versions before v4.0.3, Fixed in - v4.0.3
Debianlibpod< 3.0.1+dfsg1-3+deb11u2+1

Also affects: Enterprise Linux 8.0, 8.6, 8.4, Fedora 34, 35, 36, Openshift Container Platform 4.0

Patches

🔴Vulnerability Details

5
OSV
Podman's default inheritable capabilities for linux container not empty in github.com/containers/podman2024-08-21
OSV
CVE-2022-27649: A flaw was found in Podman, where containers were started incorrectly with non-empty default permissions2022-04-04
CVEList
CVE-2022-27649: A flaw was found in Podman, where containers were started incorrectly with non-empty default permissions2022-04-04
OSV
Podman's default inheritable capabilities for linux container not empty2022-04-01
GHSA
Podman's default inheritable capabilities for linux container not empty2022-04-01

📋Vendor Advisories

3
Microsoft
A flaw was found in Podman where containers were started incorrectly with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers were started incorrectly wit2022-04-12
Red Hat
podman: Default inheritable capabilities for linux container should be empty2022-03-30
Debian
CVE-2022-27649: libpod - A flaw was found in Podman, where containers were started incorrectly with non-e...2022