Количество 52
Количество 52

CVE-2022-29162
runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. A bug was found in runc prior to version 1.1.2 where `runc exec --cap` created processes with non-empty inheritable Linux process capabilities, creating an atypical Linux environment and enabling programs with inheritable file capabilities to elevate those capabilities to the permitted set during execve(2). This bug did not affect the container security sandbox as the inheritable set never contained more capabilities than were included in the container's bounding set. This bug has been fixed in runc 1.1.2. This fix changes `runc exec --cap` behavior such that the additional capabilities granted to the process being executed (as specified via `--cap` arguments) do not include inheritable capabilities. In addition, `runc spec` is changed to not set any inheritable capabilities in the created example OCI spec (`config.json`) file.

CVE-2022-29162
runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. A bug was found in runc prior to version 1.1.2 where `runc exec --cap` created processes with non-empty inheritable Linux process capabilities, creating an atypical Linux environment and enabling programs with inheritable file capabilities to elevate those capabilities to the permitted set during execve(2). This bug did not affect the container security sandbox as the inheritable set never contained more capabilities than were included in the container's bounding set. This bug has been fixed in runc 1.1.2. This fix changes `runc exec --cap` behavior such that the additional capabilities granted to the process being executed (as specified via `--cap` arguments) do not include inheritable capabilities. In addition, `runc spec` is changed to not set any inheritable capabilities in the created example OCI spec (`config.json`) file.

CVE-2022-29162
CVE-2022-29162
runc is a CLI tool for spawning and running containers on Linux accord ...

CVE-2022-27191
The golang.org/x/crypto/ssh package before 0.0.0-20220314234659-1baeb1ce4c0b for Go allows an attacker to crash a server in certain circumstances involving AddHostKey.

CVE-2022-27191
The golang.org/x/crypto/ssh package before 0.0.0-20220314234659-1baeb1ce4c0b for Go allows an attacker to crash a server in certain circumstances involving AddHostKey.

CVE-2022-27191
The golang.org/x/crypto/ssh package before 0.0.0-20220314234659-1baeb1ce4c0b for Go allows an attacker to crash a server in certain circumstances involving AddHostKey.
CVE-2022-27191
The golang.org/x/crypto/ssh package before 0.0.0-20220314234659-1baeb1 ...

RLSA-2022:8090
Low: runc security update
GHSA-f3fp-gc8g-vw66
Default inheritable capabilities for linux container should be empty
ELSA-2022-8090
ELSA-2022-8090: runc security update (LOW)

BDU:2022-05793
Уязвимость команды 'runc exec --cap' инструмента для запуска изолированных контейнеров Runc, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
GHSA-8c26-wmh5-6g9v
golang.org/x/crypto/ssh Denial of service via crafted Signer

BDU:2023-05840
Уязвимость компонента golang.org/x/crypto/ssh библиотеки для языка программирования Go crypto, позволяющая нарушителю вызывать отказ в обслуживании

RLSA-2022:7529
Moderate: container-tools:3.0 security update
ELSA-2022-7529
ELSA-2022-7529: container-tools:3.0 security update (MODERATE)

SUSE-SU-2022:2341-1
Security update for containerd, docker and runc

SUSE-SU-2022:2165-1
Security update for containerd

SUSE-SU-2022:4463-1
Security update for containerd

SUSE-SU-2022:4409-1
Security update for containerd
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | CVE-2022-29162 runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. A bug was found in runc prior to version 1.1.2 where `runc exec --cap` created processes with non-empty inheritable Linux process capabilities, creating an atypical Linux environment and enabling programs with inheritable file capabilities to elevate those capabilities to the permitted set during execve(2). This bug did not affect the container security sandbox as the inheritable set never contained more capabilities than were included in the container's bounding set. This bug has been fixed in runc 1.1.2. This fix changes `runc exec --cap` behavior such that the additional capabilities granted to the process being executed (as specified via `--cap` arguments) do not include inheritable capabilities. In addition, `runc spec` is changed to not set any inheritable capabilities in the created example OCI spec (`config.json`) file. | CVSS3: 5.6 | 0% Низкий | около 3 лет назад |
![]() | CVE-2022-29162 runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. A bug was found in runc prior to version 1.1.2 where `runc exec --cap` created processes with non-empty inheritable Linux process capabilities, creating an atypical Linux environment and enabling programs with inheritable file capabilities to elevate those capabilities to the permitted set during execve(2). This bug did not affect the container security sandbox as the inheritable set never contained more capabilities than were included in the container's bounding set. This bug has been fixed in runc 1.1.2. This fix changes `runc exec --cap` behavior such that the additional capabilities granted to the process being executed (as specified via `--cap` arguments) do not include inheritable capabilities. In addition, `runc spec` is changed to not set any inheritable capabilities in the created example OCI spec (`config.json`) file. | CVSS3: 5.9 | 0% Низкий | около 3 лет назад |
![]() | CVSS3: 7.8 | 0% Низкий | около 3 лет назад | |
CVE-2022-29162 runc is a CLI tool for spawning and running containers on Linux accord ... | CVSS3: 5.9 | 0% Низкий | около 3 лет назад | |
![]() | CVE-2022-27191 The golang.org/x/crypto/ssh package before 0.0.0-20220314234659-1baeb1ce4c0b for Go allows an attacker to crash a server in certain circumstances involving AddHostKey. | CVSS3: 7.5 | 0% Низкий | больше 3 лет назад |
![]() | CVE-2022-27191 The golang.org/x/crypto/ssh package before 0.0.0-20220314234659-1baeb1ce4c0b for Go allows an attacker to crash a server in certain circumstances involving AddHostKey. | CVSS3: 7.5 | 0% Низкий | больше 3 лет назад |
![]() | CVE-2022-27191 The golang.org/x/crypto/ssh package before 0.0.0-20220314234659-1baeb1ce4c0b for Go allows an attacker to crash a server in certain circumstances involving AddHostKey. | CVSS3: 7.5 | 0% Низкий | больше 3 лет назад |
CVE-2022-27191 The golang.org/x/crypto/ssh package before 0.0.0-20220314234659-1baeb1 ... | CVSS3: 7.5 | 0% Низкий | больше 3 лет назад | |
![]() | RLSA-2022:8090 Low: runc security update | 0% Низкий | больше 2 лет назад | |
GHSA-f3fp-gc8g-vw66 Default inheritable capabilities for linux container should be empty | CVSS3: 5.9 | 0% Низкий | около 3 лет назад | |
ELSA-2022-8090 ELSA-2022-8090: runc security update (LOW) | больше 2 лет назад | |||
![]() | BDU:2022-05793 Уязвимость команды 'runc exec --cap' инструмента для запуска изолированных контейнеров Runc, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании | CVSS3: 7.8 | 0% Низкий | около 3 лет назад |
GHSA-8c26-wmh5-6g9v golang.org/x/crypto/ssh Denial of service via crafted Signer | CVSS3: 7.5 | 0% Низкий | больше 3 лет назад | |
![]() | BDU:2023-05840 Уязвимость компонента golang.org/x/crypto/ssh библиотеки для языка программирования Go crypto, позволяющая нарушителю вызывать отказ в обслуживании | CVSS3: 7.5 | 0% Низкий | около 3 лет назад |
![]() | RLSA-2022:7529 Moderate: container-tools:3.0 security update | больше 2 лет назад | ||
ELSA-2022-7529 ELSA-2022-7529: container-tools:3.0 security update (MODERATE) | больше 2 лет назад | |||
![]() | SUSE-SU-2022:2341-1 Security update for containerd, docker and runc | почти 3 года назад | ||
![]() | SUSE-SU-2022:2165-1 Security update for containerd | почти 3 года назад | ||
![]() | SUSE-SU-2022:4463-1 Security update for containerd | больше 2 лет назад | ||
![]() | SUSE-SU-2022:4409-1 Security update for containerd | больше 2 лет назад |
Уязвимостей на страницу