CVE-2022-27652
published 2022-04-18CVE-2022-27652: A flaw was found in cri-o, where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine)…
PriorityP426medium5.3CVSS 3.1
AVLACLPRLUINSUCLILAL
EPSS
0.24%
15.4th percentile
A flaw was found in cri-o, where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fedoraproject | fedora | — | — |
| github.com | cri-o_cri-o | >= 0 < 1.24.0 | 1.24.0 |
| mobyproject | moby | < 20.10.14 | 20.10.14 |
| redhat | openshift_container_platform | — | — |
| redhat | openshift_container_platform | — | — |
| redhat | openshift_container_platform | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Incorrect Default Permissions in CRI-O in github.com/cri-o/cri-o
osv·2024-08-21
CVE-2022-27652 Incorrect Default Permissions in CRI-O in github.com/cri-o/cri-o
Incorrect Default Permissions in CRI-O in github.com/cri-o/cri-o
Incorrect Default Permissions in CRI-O in github.com/cri-o/cri-o
GHSA
GHSA-3wr5-8397-gqc8: The version of cri-o as released for Red Hat OpenShift Container Platform 4
ghsa_unreviewed·2023-09-15·CVSS 5.3
CVE-2022-3466 [MEDIUM] CWE-276 GHSA-3wr5-8397-gqc8: The version of cri-o as released for Red Hat OpenShift Container Platform 4
The version of cri-o as released for Red Hat OpenShift Container Platform 4.9.48, 4.10.31, and 4.11.6 via RHBA-2022:6316, RHBA-2022:6257, and RHBA-2022:6658, respectively, included an incorrect version of cri-o missing the fix for CVE-2022-27652, which was previously fixed in OCP 4.9.41 and 4.10.12 via RHBA-2022:5433 and RHSA-2022:1600. This issue could allow an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs. For more details, see https://access.redhat.com/security/cve/CVE-2022-27652.
OSV
Incorrect Default Permissions in CRI-O
osv·2022-04-22
CVE-2022-27652 [MEDIUM] Incorrect Default Permissions in CRI-O
Incorrect Default Permissions in CRI-O
### Impact
A bug was found in CRI-O where containers were incorrectly started with non-empty inheritable Linux process capabilities, creating an atypical Linux environment and enabling programs with inheritable file capabilities to elevate those capabilities to the permitted set during `execve(2)`. Normally, when executable programs have specified permitted file capabilities, otherwise unprivileged users and processes can execute those programs and gain the specified file capabilities up to the bounding set. Due to this bug, containers which included executable programs with inheritable file capabilities allowed otherwise unprivileged users and processes to additionally gain these inheritable file capabilities up to the container's bounding set. Con
GHSA
Incorrect Default Permissions in CRI-O
ghsa·2022-04-22
CVE-2022-27652 [MEDIUM] CWE-276 Incorrect Default Permissions in CRI-O
Incorrect Default Permissions in CRI-O
### Impact
A bug was found in CRI-O where containers were incorrectly started with non-empty inheritable Linux process capabilities, creating an atypical Linux environment and enabling programs with inheritable file capabilities to elevate those capabilities to the permitted set during `execve(2)`. Normally, when executable programs have specified permitted file capabilities, otherwise unprivileged users and processes can execute those programs and gain the specified file capabilities up to the bounding set. Due to this bug, containers which included executable programs with inheritable file capabilities allowed otherwise unprivileged users and processes to additionally gain these inheritable file capabilities up to the container's bounding set. Con
Red Hat
cri-o: Security regression of CVE-2022-27652
vendor_redhat·2022-10-12·CVSS 5.3
CVE-2022-3466 [MEDIUM] CWE-276 cri-o: Security regression of CVE-2022-27652
cri-o: Security regression of CVE-2022-27652
The version of cri-o as released for Red Hat OpenShift Container Platform 4.9.48, 4.10.31, and 4.11.6 via RHBA-2022:6316, RHBA-2022:6257, and RHBA-2022:6658, respectively, included an incorrect version of cri-o missing the fix for CVE-2022-27652, which was previously fixed in OCP 4.9.41 and 4.10.12 via RHBA-2022:5433 and RHSA-2022:1600. This issue could allow an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs. For more details, see https://access.redhat.com/security/cve/CVE-2022-27652.
The version of cri-o as released for Red Hat OpenShift Container Platform 4.9.48, 4.10.31, and 4.11.6 via RHBA-2022:6316, RHBA-2022:6257, and RHBA-2022:6658, respectively,
Red Hat
cri-o: Default inheritable capabilities for linux container should be empty
vendor_redhat·2022-03-30·CVSS 5.9
CVE-2022-27652 [MEDIUM] CWE-276 cri-o: Default inheritable capabilities for linux container should be empty
cri-o: Default inheritable capabilities for linux container should be empty
A flaw was found in cri-o, where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs.
A flaw was found in cri-o, where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritabl
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-04-18
Published