VDB
RHSA-2022%3A1363
RHSA-2022%3A1363
PUBLISHED
CVSS 4.800000190734863 MEDIUM
A flaw was found in Moby (Docker Engine), where containers were started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs. Containers using Linux users and groups to perform privilege separation inside the container are most directly impacted.
Risk Scores
CVSS 3.1
4.800000190734863
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | openshift4/ose-cluster-authentication-operator@sha256:aff3779051f13d89fd6ad1181ec85a5d137b060cadee14c9de4320d4ba57906e_ppc64le as a component of Red Hat OpenShift Container Platform 4.9 | *, * |
| Red Hat | openshift4/ose-service-ca-operator@sha256:986569745c7512f405ed650015cb3e888046886d6cc88795a133dc3cffb20626_amd64 as a component of Red Hat OpenShift Container Platform 4.9 | *, openshift4/ose-service-ca-operator@sha256:986569745c7512f405ed650015cb3e888046886d6cc88795a133dc3cffb20626_amd64 |
| Red Hat | openshift4/ose-jenkins@sha256:d5a7e7700df60f99e6e6ad7e52044de02a1e46e634ea4467d6bc692702bc01cf_s390x as a component of Red Hat OpenShift Container Platform 4.9 | openshift4/ose-jenkins@sha256:d5a7e7700df60f99e6e6ad7e52044de02a1e46e634ea4467d6bc692702bc01cf_s390x, * |
| Red Hat | openshift4/ose-libvirt-machine-controllers@sha256:9c44e3aca15f1b679ae903d08e69e6f81b584b69c00ad9f74a0d4e68dc1a91c8_ppc64le as a component of Red Hat OpenShift Container Platform 4.9 | *, openshift4/ose-libvirt-machine-controllers@sha256:9c44e3aca15f1b679ae903d08e69e6f81b584b69c00ad9f74a0d4e68dc1a91c8_ppc64le |
| Red Hat | openshift4/ose-cluster-config-operator@sha256:fa758959de957deac6033474ef15eaf0930c7a3090a5676e214db43efd3cef75_ppc64le as a component of Red Hat OpenShift Container Platform 4.9 | openshift4/ose-cluster-config-operator@sha256:fa758959de957deac6033474ef15eaf0930c7a3090a5676e214db43efd3cef75_ppc64le, * |
| Red Hat | openshift4/ose-csi-livenessprobe@sha256:9fe99c9cc2dfe02bc594cdcd7b9dd171250675b78d1dcf22078be3ef0f32027e_ppc64le as a component of Red Hat OpenShift Container Platform 4.9 | *, openshift4/ose-csi-livenessprobe@sha256:9fe99c9cc2dfe02bc594cdcd7b9dd171250675b78d1dcf22078be3ef0f32027e_ppc64le |
| Red Hat | openshift4/ose-cluster-kube-controller-manager-operator@sha256:d442781803c9556840334c21e2a2eabbc4bb2aa23450f792228957c899a17241_arm64 as a component of Red Hat OpenShift Container Platform 4.9 | openshift4/ose-cluster-kube-controller-manager-operator@sha256:d442781803c9556840334c21e2a2eabbc4bb2aa23450f792228957c899a17241_arm64, * |
| Red Hat | openshift4/ose-multus-networkpolicy-rhel8@sha256:5ae53a9569ae754a6ecb3e23f9663fa2b925c42861ee033b23cdc659582b3f43_ppc64le as a component of Red Hat OpenShift Container Platform 4.9 | *, * |
| Red Hat | openshift4/ose-local-storage-operator@sha256:19d2cde9bd7b4accbfff06efa56fa02400ebf8433894493cb01fb9b930e89626_ppc64le as a component of Red Hat OpenShift Container Platform 4.9 | *, * |
| Red Hat | openshift4/ose-cluster-kube-apiserver-operator@sha256:e3f6fe4fe88cfff7ca9d2ee99663f0c129d197850fa29c4756c054101fb7f778_amd64 as a component of Red Hat OpenShift Container Platform 4.9 | openshift4/ose-cluster-kube-apiserver-operator@sha256:e3f6fe4fe88cfff7ca9d2ee99663f0c129d197850fa29c4756c054101fb7f778_amd64, * |
| Red Hat | openshift4/ose-telemeter@sha256:59cc372a536fa06a7244d50eaa606de95f7b9bc68cb6a1b0d607e44b07e52e91_arm64 as a component of Red Hat OpenShift Container Platform 4.9 | openshift4/ose-telemeter@sha256:59cc372a536fa06a7244d50eaa606de95f7b9bc68cb6a1b0d607e44b07e52e91_arm64, * |
| Red Hat | openshift4/ose-multus-admission-controller@sha256:6ab62fbc1153d030bbba4cd2b051b7d709f03dd05680efe7e444d45bb30b6518_arm64 as a component of Red Hat OpenShift Container Platform 4.9 | openshift4/ose-multus-admission-controller@sha256:6ab62fbc1153d030bbba4cd2b051b7d709f03dd05680efe7e444d45bb30b6518_arm64, * |
| Red Hat | openshift4/ose-installer@sha256:42080c05aa7620498c403088a9fc446048daa53f82a71d7bd48fe5cf5f18353e_s390x as a component of Red Hat OpenShift Container Platform 4.9 | openshift4/ose-installer@sha256:42080c05aa7620498c403088a9fc446048daa53f82a71d7bd48fe5cf5f18353e_s390x, * |
| Red Hat | openshift4/ose-console@sha256:4fcab9a2326d8c85724682a9b8609acb58bb855842966d06d4c4342a6cc8dcbc_ppc64le as a component of Red Hat OpenShift Container Platform 4.9 | openshift4/ose-console@sha256:4fcab9a2326d8c85724682a9b8609acb58bb855842966d06d4c4342a6cc8dcbc_ppc64le, * |
| Red Hat | openshift4/ose-machine-config-operator@sha256:016ed3a0226a13a7790f85ec83852b1da42d6d94cd38d2ecc5533d1e1e6ac357_amd64 as a component of Red Hat OpenShift Container Platform 4.9 | *, openshift4/ose-machine-config-operator@sha256:016ed3a0226a13a7790f85ec83852b1da42d6d94cd38d2ecc5533d1e1e6ac357_amd64 |
| Red Hat | openshift4/ose-openshift-controller-manager-rhel8@sha256:f52cbbbff6653b1299f0949da7a0bac5caf7f11ddd6e3ec8a67b50538b4b7d2a_s390x as a component of Red Hat OpenShift Container Platform 4.9 | *, openshift4/ose-openshift-controller-manager-rhel8@sha256:f52cbbbff6653b1299f0949da7a0bac5caf7f11ddd6e3ec8a67b50538b4b7d2a_s390x |
| Red Hat | openshift4/ose-openshift-apiserver-rhel8@sha256:1d47bd47038aa98cff65d6e7ad9db4ec87c82fcf7519e58d130e0ff96329d1ff_amd64 as a component of Red Hat OpenShift Container Platform 4.9 | *, * |
| Red Hat | openshift4/ose-openshift-state-metrics-rhel8@sha256:5dfb1f69bb9f1c64abb93a0cb58d82ec34985594a0a911ed23a3aab74270cf29_s390x as a component of Red Hat OpenShift Container Platform 4.9 | *, * |
| Red Hat | openshift4/ose-aws-machine-controllers@sha256:42282c2aa60e18dd570d2f8a4d8dc33d31758755403837fff6c1cfe85c05fa6e_amd64 as a component of Red Hat OpenShift Container Platform 4.9 | *, * |
| Red Hat | openshift4/ose-csi-external-provisioner-rhel8@sha256:f14451dd2d18232a930c6daaed4ca5d7b65c9e5f931c03a1606d8c6c438f7bdc_arm64 as a component of Red Hat OpenShift Container Platform 4.9 | *, * |
…and 520 more
Timeline
- Apr 20, 2022 CVE Published
- May 1, 2026 Distribution Patch
- May 1, 2026 Distribution Patch
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
- May 15, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2022:1363 advisory
- https://access.redhat.com/security/updates/classification/#moderate advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2021595 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2036609 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2059700 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2062310 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2063327 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2064408 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2066837 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2069498 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2070277 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2070617 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2071692 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2072995 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2073967 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2022/rhsa-2022_1363.json advisory
- https://access.redhat.com/security/cve/CVE-2022-24769 advisory
- https://www.cve.org/CVERecord?id=CVE-2022-24769 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-24769 advisory
- https://github.com/moby/moby/security/advisories/GHSA-2mm7-x5h6-5pvq advisory