VDB

RHSA-2022%3A1622

RHSA-2022%3A1622 PUBLISHED CVSS 4.800000190734863 MEDIUM

A flaw was found in Moby (Docker Engine), where containers were started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs. Containers using Linux users and groups to perform privilege separation inside the container are most directly impacted.

Risk Scores

CVSS 3.1
4.800000190734863
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersions
Red Hatopenshift4/ose-vertical-pod-autoscaler-rhel8-operator@sha256:d5d1805247ddbe0c0d5744a8a0e97aee20b25bcdd898688028f885df081a0b39_amd64 as a component of Red Hat OpenShift Container Platform 4.6*, *
Red Hatopenshift4/ose-logging-fluentd@sha256:dde297c26e43080554018dae0dd046da85a5454f6ee09f000cd8af0a87c8d537_ppc64le as a component of Red Hat OpenShift Container Platform 4.6*, openshift4/ose-logging-fluentd@sha256:dde297c26e43080554018dae0dd046da85a5454f6ee09f000cd8af0a87c8d537_ppc64le
Red Hatopenshift4/ose-egress-dns-proxy@sha256:31abdecafc822241cdc33d58affa79378b0589467bbf2641664c25f8de0fc337_ppc64le as a component of Red Hat OpenShift Container Platform 4.6openshift4/ose-egress-dns-proxy@sha256:31abdecafc822241cdc33d58affa79378b0589467bbf2641664c25f8de0fc337_ppc64le, *
Red Hatopenshift4/ose-elasticsearch-operator@sha256:ddc044378f825b9b155f9630084eadb3a894a85d3225f0ada15d8526cd70f632_amd64 as a component of Red Hat OpenShift Container Platform 4.6*, *
Red Hatopenshift4/ose-vertical-pod-autoscaler-rhel8@sha256:733c559de39e1838cc4673277162d420677fd6c38a7b4ddc4c96476436b9566a_amd64 as a component of Red Hat OpenShift Container Platform 4.6openshift4/ose-vertical-pod-autoscaler-rhel8@sha256:733c559de39e1838cc4673277162d420677fd6c38a7b4ddc4c96476436b9566a_amd64, *
Red Hatopenshift4/ose-helm-operator@sha256:f263f983286c165aa1b59a90723514a0fb1dbfc264f32a89dd3a05b691890abb_s390x as a component of Red Hat OpenShift Container Platform 4.6*, openshift4/ose-helm-operator@sha256:f263f983286c165aa1b59a90723514a0fb1dbfc264f32a89dd3a05b691890abb_s390x
Red Hatopenshift4/ose-node-feature-discovery@sha256:33809894045d1dacc8fbacc12dc4fa4b9ee04dd52da271b4a8f10277c41fc493_amd64 as a component of Red Hat OpenShift Container Platform 4.6*, openshift4/ose-node-feature-discovery@sha256:33809894045d1dacc8fbacc12dc4fa4b9ee04dd52da271b4a8f10277c41fc493_amd64
Red Hatopenshift4/ose-metering-helm-container-rhel8@sha256:36fc4defba4e1c7c858fc0e50d280095a9afc32d7db39d23d4e08507f0f6f29a_amd64 as a component of Red Hat OpenShift Container Platform 4.6*, openshift4/ose-metering-helm-container-rhel8@sha256:36fc4defba4e1c7c858fc0e50d280095a9afc32d7db39d23d4e08507f0f6f29a_amd64
Red Hatopenshift4/ose-logging-fluentd@sha256:7a064e87495743e9ca8aac591804faa80bae1d8cd6f6bf9621eaac8a92b44487_amd64 as a component of Red Hat OpenShift Container Platform 4.6*, openshift4/ose-logging-fluentd@sha256:7a064e87495743e9ca8aac591804faa80bae1d8cd6f6bf9621eaac8a92b44487_amd64
Red Hatopenshift4/ose-sriov-operator-must-gather@sha256:485c7bca99d2a2e83601b0c53b2cbdaa4a65972f521114efb3b2c86a86666a3c_ppc64le as a component of Red Hat OpenShift Container Platform 4.6*, openshift4/ose-sriov-operator-must-gather@sha256:485c7bca99d2a2e83601b0c53b2cbdaa4a65972f521114efb3b2c86a86666a3c_ppc64le
Red Hatopenshift4/ose-node-feature-discovery@sha256:7c979a01b697d8bcaf9adf93cef6b9454bf9acf1e7c5fa5f7b236d8fad2f5336_ppc64le as a component of Red Hat OpenShift Container Platform 4.6*, openshift4/ose-node-feature-discovery@sha256:7c979a01b697d8bcaf9adf93cef6b9454bf9acf1e7c5fa5f7b236d8fad2f5336_ppc64le
Red Hatopenshift4/ose-sriov-dp-admission-controller@sha256:814dfd28c504879d0ab2368ea31b2871c868fcd482c06d8abf73e046dfab3ba7_ppc64le as a component of Red Hat OpenShift Container Platform 4.6openshift4/ose-sriov-dp-admission-controller@sha256:814dfd28c504879d0ab2368ea31b2871c868fcd482c06d8abf73e046dfab3ba7_ppc64le, *
Red Hatopenshift4/ose-elasticsearch-operator@sha256:e82702613ced53d2482405211bdd6751a0a07bb720ad504986f1b2b3c4b027df_s390x as a component of Red Hat OpenShift Container Platform 4.6*, openshift4/ose-elasticsearch-operator@sha256:e82702613ced53d2482405211bdd6751a0a07bb720ad504986f1b2b3c4b027df_s390x
Red Hatopenshift4/ose-ptp@sha256:8321ef62bb9da1a24ea345c030e307e6326fa1f7be759c12322c0fa719cea6ae_amd64 as a component of Red Hat OpenShift Container Platform 4.6*, openshift4/ose-ptp@sha256:8321ef62bb9da1a24ea345c030e307e6326fa1f7be759c12322c0fa719cea6ae_amd64
Red Hatopenshift4/ose-elasticsearch-proxy@sha256:dca856b265c1b95dcea151b8367cf30b84c0d11df098f61a819d4f81e324d3f2_amd64 as a component of Red Hat OpenShift Container Platform 4.6*, openshift4/ose-elasticsearch-proxy@sha256:dca856b265c1b95dcea151b8367cf30b84c0d11df098f61a819d4f81e324d3f2_amd64
Red Hatopenshift4/ose-logging-kibana6@sha256:8e2e9944c739b58cc9a01a5ca07c1db83d2a2ba4aee9453d97e0aa1f1f11bbbb_amd64 as a component of Red Hat OpenShift Container Platform 4.6*, *
Red Hatopenshift4/ose-cluster-nfd-operator@sha256:196e55ab840af28d507a1f6da9419ce874d4aa73c3c18a8d07ce3b2bf5ea275f_s390x as a component of Red Hat OpenShift Container Platform 4.6openshift4/ose-cluster-nfd-operator@sha256:196e55ab840af28d507a1f6da9419ce874d4aa73c3c18a8d07ce3b2bf5ea275f_s390x, *
Red Hatopenshift4/ose-logging-curator5@sha256:9eeebbf7be02555a153a50760a0a2c66ef2c210ec111bfaebaa830d94ac3d60b_ppc64le as a component of Red Hat OpenShift Container Platform 4.6*, openshift4/ose-logging-curator5@sha256:9eeebbf7be02555a153a50760a0a2c66ef2c210ec111bfaebaa830d94ac3d60b_ppc64le
Red Hatopenshift4/ose-sriov-network-config-daemon@sha256:9258fe2c89824fde2b55c00066c882f785385a1c194ba455924946fa077e3cf1_amd64 as a component of Red Hat OpenShift Container Platform 4.6*, *
Red Hatopenshift4/ose-sriov-network-device-plugin@sha256:ac2518a8f89a1ba77a44cf84e7a7096ef7cb3b3ea9fe2997c64e26503591635b_amd64 as a component of Red Hat OpenShift Container Platform 4.6*, openshift4/ose-sriov-network-device-plugin@sha256:ac2518a8f89a1ba77a44cf84e7a7096ef7cb3b3ea9fe2997c64e26503591635b_amd64

…and 106 more

Timeline

  • May 4, 2022 CVE Published
  • May 1, 2026 Distribution Patch
  • May 1, 2026 Distribution Patch
  • May 1, 2026 Security Advisory
  • May 1, 2026 Security Advisory
  • May 15, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›