Логотип exploitDog
bind:"CVE-2022-1708" OR bind:"CVE-2022-27191" OR bind:"CVE-2022-29162"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2022-1708" OR bind:"CVE-2022-27191" OR bind:"CVE-2022-29162"

Количество 52

Количество 52

redhat логотип

CVE-2022-29162

около 3 лет назад

runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. A bug was found in runc prior to version 1.1.2 where `runc exec --cap` created processes with non-empty inheritable Linux process capabilities, creating an atypical Linux environment and enabling programs with inheritable file capabilities to elevate those capabilities to the permitted set during execve(2). This bug did not affect the container security sandbox as the inheritable set never contained more capabilities than were included in the container's bounding set. This bug has been fixed in runc 1.1.2. This fix changes `runc exec --cap` behavior such that the additional capabilities granted to the process being executed (as specified via `--cap` arguments) do not include inheritable capabilities. In addition, `runc spec` is changed to not set any inheritable capabilities in the created example OCI spec (`config.json`) file.

CVSS3: 5.6
EPSS: Низкий
nvd логотип

CVE-2022-29162

около 3 лет назад

runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. A bug was found in runc prior to version 1.1.2 where `runc exec --cap` created processes with non-empty inheritable Linux process capabilities, creating an atypical Linux environment and enabling programs with inheritable file capabilities to elevate those capabilities to the permitted set during execve(2). This bug did not affect the container security sandbox as the inheritable set never contained more capabilities than were included in the container's bounding set. This bug has been fixed in runc 1.1.2. This fix changes `runc exec --cap` behavior such that the additional capabilities granted to the process being executed (as specified via `--cap` arguments) do not include inheritable capabilities. In addition, `runc spec` is changed to not set any inheritable capabilities in the created example OCI spec (`config.json`) file.

CVSS3: 5.9
EPSS: Низкий
msrc логотип

CVE-2022-29162

около 3 лет назад

CVSS3: 7.8
EPSS: Низкий
debian логотип

CVE-2022-29162

около 3 лет назад

runc is a CLI tool for spawning and running containers on Linux accord ...

CVSS3: 5.9
EPSS: Низкий
ubuntu логотип

CVE-2022-27191

больше 3 лет назад

The golang.org/x/crypto/ssh package before 0.0.0-20220314234659-1baeb1ce4c0b for Go allows an attacker to crash a server in certain circumstances involving AddHostKey.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2022-27191

больше 3 лет назад

The golang.org/x/crypto/ssh package before 0.0.0-20220314234659-1baeb1ce4c0b for Go allows an attacker to crash a server in certain circumstances involving AddHostKey.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2022-27191

больше 3 лет назад

The golang.org/x/crypto/ssh package before 0.0.0-20220314234659-1baeb1ce4c0b for Go allows an attacker to crash a server in certain circumstances involving AddHostKey.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2022-27191

больше 3 лет назад

The golang.org/x/crypto/ssh package before 0.0.0-20220314234659-1baeb1 ...

CVSS3: 7.5
EPSS: Низкий
rocky логотип

RLSA-2022:8090

больше 2 лет назад

Low: runc security update

EPSS: Низкий
github логотип

GHSA-f3fp-gc8g-vw66

около 3 лет назад

Default inheritable capabilities for linux container should be empty

CVSS3: 5.9
EPSS: Низкий
oracle-oval логотип

ELSA-2022-8090

больше 2 лет назад

ELSA-2022-8090: runc security update (LOW)

EPSS: Низкий
fstec логотип

BDU:2022-05793

около 3 лет назад

Уязвимость команды 'runc exec --cap' инструмента для запуска изолированных контейнеров Runc, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-8c26-wmh5-6g9v

больше 3 лет назад

golang.org/x/crypto/ssh Denial of service via crafted Signer

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2023-05840

около 3 лет назад

Уязвимость компонента golang.org/x/crypto/ssh библиотеки для языка программирования Go crypto, позволяющая нарушителю вызывать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий
rocky логотип

RLSA-2022:7529

больше 2 лет назад

Moderate: container-tools:3.0 security update

EPSS: Низкий
oracle-oval логотип

ELSA-2022-7529

больше 2 лет назад

ELSA-2022-7529: container-tools:3.0 security update (MODERATE)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:2341-1

почти 3 года назад

Security update for containerd, docker and runc

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:2165-1

почти 3 года назад

Security update for containerd

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:4463-1

больше 2 лет назад

Security update for containerd

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:4409-1

больше 2 лет назад

Security update for containerd

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2022-29162

runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. A bug was found in runc prior to version 1.1.2 where `runc exec --cap` created processes with non-empty inheritable Linux process capabilities, creating an atypical Linux environment and enabling programs with inheritable file capabilities to elevate those capabilities to the permitted set during execve(2). This bug did not affect the container security sandbox as the inheritable set never contained more capabilities than were included in the container's bounding set. This bug has been fixed in runc 1.1.2. This fix changes `runc exec --cap` behavior such that the additional capabilities granted to the process being executed (as specified via `--cap` arguments) do not include inheritable capabilities. In addition, `runc spec` is changed to not set any inheritable capabilities in the created example OCI spec (`config.json`) file.

CVSS3: 5.6
0%
Низкий
около 3 лет назад
nvd логотип
CVE-2022-29162

runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. A bug was found in runc prior to version 1.1.2 where `runc exec --cap` created processes with non-empty inheritable Linux process capabilities, creating an atypical Linux environment and enabling programs with inheritable file capabilities to elevate those capabilities to the permitted set during execve(2). This bug did not affect the container security sandbox as the inheritable set never contained more capabilities than were included in the container's bounding set. This bug has been fixed in runc 1.1.2. This fix changes `runc exec --cap` behavior such that the additional capabilities granted to the process being executed (as specified via `--cap` arguments) do not include inheritable capabilities. In addition, `runc spec` is changed to not set any inheritable capabilities in the created example OCI spec (`config.json`) file.

CVSS3: 5.9
0%
Низкий
около 3 лет назад
msrc логотип
CVSS3: 7.8
0%
Низкий
около 3 лет назад
debian логотип
CVE-2022-29162

runc is a CLI tool for spawning and running containers on Linux accord ...

CVSS3: 5.9
0%
Низкий
около 3 лет назад
ubuntu логотип
CVE-2022-27191

The golang.org/x/crypto/ssh package before 0.0.0-20220314234659-1baeb1ce4c0b for Go allows an attacker to crash a server in certain circumstances involving AddHostKey.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
redhat логотип
CVE-2022-27191

The golang.org/x/crypto/ssh package before 0.0.0-20220314234659-1baeb1ce4c0b for Go allows an attacker to crash a server in certain circumstances involving AddHostKey.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-27191

The golang.org/x/crypto/ssh package before 0.0.0-20220314234659-1baeb1ce4c0b for Go allows an attacker to crash a server in certain circumstances involving AddHostKey.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-27191

The golang.org/x/crypto/ssh package before 0.0.0-20220314234659-1baeb1 ...

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
rocky логотип
RLSA-2022:8090

Low: runc security update

0%
Низкий
больше 2 лет назад
github логотип
GHSA-f3fp-gc8g-vw66

Default inheritable capabilities for linux container should be empty

CVSS3: 5.9
0%
Низкий
около 3 лет назад
oracle-oval логотип
ELSA-2022-8090

ELSA-2022-8090: runc security update (LOW)

больше 2 лет назад
fstec логотип
BDU:2022-05793

Уязвимость команды 'runc exec --cap' инструмента для запуска изолированных контейнеров Runc, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

CVSS3: 7.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-8c26-wmh5-6g9v

golang.org/x/crypto/ssh Denial of service via crafted Signer

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
fstec логотип
BDU:2023-05840

Уязвимость компонента golang.org/x/crypto/ssh библиотеки для языка программирования Go crypto, позволяющая нарушителю вызывать отказ в обслуживании

CVSS3: 7.5
0%
Низкий
около 3 лет назад
rocky логотип
RLSA-2022:7529

Moderate: container-tools:3.0 security update

больше 2 лет назад
oracle-oval логотип
ELSA-2022-7529

ELSA-2022-7529: container-tools:3.0 security update (MODERATE)

больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2022:2341-1

Security update for containerd, docker and runc

почти 3 года назад
suse-cvrf логотип
SUSE-SU-2022:2165-1

Security update for containerd

почти 3 года назад
suse-cvrf логотип
SUSE-SU-2022:4463-1

Security update for containerd

больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2022:4409-1

Security update for containerd

больше 2 лет назад

Уязвимостей на страницу