Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-27651

Опубликовано: 30 мар. 2022
Источник: redhat
CVSS3: 4.8
EPSS Низкий

Описание

A flaw was found in buildah where containers were incorrectly started with non-empty default permissions. A bug was found in Moby (Docker Engine) where containers were incorrectly started with non-empty inheritable Linux process capabilities, enabling an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs. This has the potential to impact confidentiality and integrity.

A flaw was found in buildah, where containers were incorrectly started with non-empty default permissions. A bug was found in Moby (Docker Engine) where containers were incorrectly started with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs.

Отчет

This issue is related to the general vulnerability found in Moby (Docker Engine), which has been assigned CVE-2022-24769. The impact for OpenShift Container Platform is set to LOW as Buildah was shipped but is not being used. No update is planned at this time.

Меры по смягчению последствий

The entry point of a container can be modified to use a utility like capsh(1) to drop inheritable capabilities prior to the primary process starting.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7buildahAffected
Red Hat Enterprise Linux 8container-tools:4.0/buildahNot affected
Red Hat Enterprise Linux 9buildahNot affected
Red Hat OpenShift Container Platform 4buildahWill not fix
Red Hat Enterprise Linux 8container-toolsFixedRHSA-2022:156526.04.2022
Red Hat Enterprise Linux 8container-toolsFixedRHSA-2022:156626.04.2022
Red Hat Enterprise Linux 8container-toolsFixedRHSA-2022:176210.05.2022
Red Hat Enterprise Linux 8.2 Extended Update Supportcontainer-toolsFixedRHSA-2022:465118.05.2022
Red Hat Enterprise Linux 8.4 Extended Update Supportcontainer-toolsFixedRHSA-2022:140719.04.2022
Red Hat Enterprise Linux 8.4 Extended Update Supportcontainer-toolsFixedRHSA-2022:481631.05.2022

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-276
https://bugzilla.redhat.com/show_bug.cgi?id=2066840buildah: Default inheritable capabilities for linux container should be empty

EPSS

Процентиль: 29%
0.001
Низкий

4.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.8
ubuntu
около 3 лет назад

A flaw was found in buildah where containers were incorrectly started with non-empty default permissions. A bug was found in Moby (Docker Engine) where containers were incorrectly started with non-empty inheritable Linux process capabilities, enabling an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs. This has the potential to impact confidentiality and integrity.

CVSS3: 6.8
nvd
около 3 лет назад

A flaw was found in buildah where containers were incorrectly started with non-empty default permissions. A bug was found in Moby (Docker Engine) where containers were incorrectly started with non-empty inheritable Linux process capabilities, enabling an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs. This has the potential to impact confidentiality and integrity.

CVSS3: 6.8
msrc
больше 2 лет назад

Описание отсутствует

CVSS3: 6.8
debian
около 3 лет назад

A flaw was found in buildah where containers were incorrectly started ...

suse-cvrf
почти 3 года назад

Security update for buildah

EPSS

Процентиль: 29%
0.001
Низкий

4.8 Medium

CVSS3