Описание
A flaw was found in Podman, where containers were started incorrectly with non-empty default permissions. A vulnerability was found in Moby (Docker Engine), where containers were started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs.
Релиз | Статус | Примечание |
---|---|---|
devel | DNE | |
esm-apps/jammy | needs-triage | |
esm-apps/noble | needs-triage | |
impish | ignored | end of life |
jammy | needs-triage | |
kinetic | ignored | end of life, was needs-triage |
lunar | ignored | end of life, was needs-triage |
mantic | ignored | end of life, was needs-triage |
noble | needs-triage | |
oracular | needs-triage |
Показывать по
Ссылки на источники
6 Medium
CVSS2
7.5 High
CVSS3
Связанные уязвимости
A flaw was found in Podman, where containers were started incorrectly with non-empty default permissions. A vulnerability was found in Moby (Docker Engine), where containers were started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs.
A flaw was found in Podman, where containers were started incorrectly with non-empty default permissions. A vulnerability was found in Moby (Docker Engine), where containers were started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs.
A flaw was found in Podman, where containers were started incorrectly ...
Podman's default inheritable capabilities for linux container not empty
6 Medium
CVSS2
7.5 High
CVSS3