VDB

CVE-2022-27650

CVE-2022-27650 PUBLISHED

Reported by redhat · Published April 4, 2022

A flaw was found in crun where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers were started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs.

Affected Products

VendorProductVersions
n/acrunAffects crun v1.4.3 and prior, Fixed in – v1.4.4
n/acrunAffects crun v1.4.3 and prior, Fixed in – v1.4.4
alpinecrun0, 0, 0

Timeline

  • Apr 4, 2022 CVE Published
  • Apr 5, 2022 EPSS Score
  • May 26, 2022 EPSS Score
  • Jul 16, 2022 EPSS Score
  • Sep 5, 2022 EPSS Score
  • Oct 25, 2022 EPSS Score
  • Dec 15, 2022 EPSS Score
  • Feb 3, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Mar 26, 2023 EPSS Score
  • May 15, 2023 EPSS Score
  • Jul 5, 2023 EPSS Score

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›