VDB

CVE-2022-27651

CVE-2022-27651 PUBLISHED CVSS 6.800000190734863 MEDIUM

Reported by redhat · Published April 4, 2022

A flaw was found in buildah where containers were incorrectly started with non-empty default permissions. A bug was found in Moby (Docker Engine) where containers were incorrectly started with non-empty inheritable Linux process capabilities, enabling an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs. This has the potential to impact confidentiality and integrity.

Risk Scores

CVSS 3.1
6.800000190734863
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N

Affected Products

VendorProductVersions
n/abuildahAffects buildah v1.24.0 and prior, Fixed in - v1.25.0
n/abuildahAffects buildah v1.24.0 and prior, Fixed in - v1.25.0, Affects buildah v1.24.0 and prior, Fixed in - v1.25.0, Affects buildah v1.24.0 and prior, Fixed in - v1.25.0
github.comcontainers/buildah0, 0, 0
chainguardbuildah*, *, *
github.comcontainers/buildah/chroot0, 0, 0
wolfibuildah*, *, *
alpinebuildah0

Timeline

  • Apr 1, 2022 CVE Published
  • Apr 5, 2022 EPSS Score
  • May 26, 2022 EPSS Score
  • Jul 16, 2022 EPSS Score
  • Sep 5, 2022 EPSS Score
  • Oct 25, 2022 EPSS Score
  • Dec 30, 2022 EPSS Score
  • Feb 3, 2023 EPSS Score
  • Feb 23, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Mar 26, 2023 EPSS Score
  • May 15, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›