VDB
RHSA-2022%3A1622
RHSA-2022%3A1622
PUBLISHED
CVSS 4.800000190734863 MEDIUM
A flaw was found in Moby (Docker Engine), where containers were started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs. Containers using Linux users and groups to perform privilege separation inside the container are most directly impacted.
Risk Scores
CVSS 3.1
4.800000190734863
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | openshift4/ose-vertical-pod-autoscaler-rhel8-operator@sha256:d5d1805247ddbe0c0d5744a8a0e97aee20b25bcdd898688028f885df081a0b39_amd64 as a component of Red Hat OpenShift Container Platform 4.6 | *, * |
| Red Hat | openshift4/ose-logging-fluentd@sha256:dde297c26e43080554018dae0dd046da85a5454f6ee09f000cd8af0a87c8d537_ppc64le as a component of Red Hat OpenShift Container Platform 4.6 | *, openshift4/ose-logging-fluentd@sha256:dde297c26e43080554018dae0dd046da85a5454f6ee09f000cd8af0a87c8d537_ppc64le |
| Red Hat | openshift4/ose-egress-dns-proxy@sha256:31abdecafc822241cdc33d58affa79378b0589467bbf2641664c25f8de0fc337_ppc64le as a component of Red Hat OpenShift Container Platform 4.6 | openshift4/ose-egress-dns-proxy@sha256:31abdecafc822241cdc33d58affa79378b0589467bbf2641664c25f8de0fc337_ppc64le, * |
| Red Hat | openshift4/ose-elasticsearch-operator@sha256:ddc044378f825b9b155f9630084eadb3a894a85d3225f0ada15d8526cd70f632_amd64 as a component of Red Hat OpenShift Container Platform 4.6 | *, * |
| Red Hat | openshift4/ose-vertical-pod-autoscaler-rhel8@sha256:733c559de39e1838cc4673277162d420677fd6c38a7b4ddc4c96476436b9566a_amd64 as a component of Red Hat OpenShift Container Platform 4.6 | openshift4/ose-vertical-pod-autoscaler-rhel8@sha256:733c559de39e1838cc4673277162d420677fd6c38a7b4ddc4c96476436b9566a_amd64, * |
| Red Hat | openshift4/ose-helm-operator@sha256:f263f983286c165aa1b59a90723514a0fb1dbfc264f32a89dd3a05b691890abb_s390x as a component of Red Hat OpenShift Container Platform 4.6 | *, openshift4/ose-helm-operator@sha256:f263f983286c165aa1b59a90723514a0fb1dbfc264f32a89dd3a05b691890abb_s390x |
| Red Hat | openshift4/ose-node-feature-discovery@sha256:33809894045d1dacc8fbacc12dc4fa4b9ee04dd52da271b4a8f10277c41fc493_amd64 as a component of Red Hat OpenShift Container Platform 4.6 | *, openshift4/ose-node-feature-discovery@sha256:33809894045d1dacc8fbacc12dc4fa4b9ee04dd52da271b4a8f10277c41fc493_amd64 |
| Red Hat | openshift4/ose-metering-helm-container-rhel8@sha256:36fc4defba4e1c7c858fc0e50d280095a9afc32d7db39d23d4e08507f0f6f29a_amd64 as a component of Red Hat OpenShift Container Platform 4.6 | *, openshift4/ose-metering-helm-container-rhel8@sha256:36fc4defba4e1c7c858fc0e50d280095a9afc32d7db39d23d4e08507f0f6f29a_amd64 |
| Red Hat | openshift4/ose-logging-fluentd@sha256:7a064e87495743e9ca8aac591804faa80bae1d8cd6f6bf9621eaac8a92b44487_amd64 as a component of Red Hat OpenShift Container Platform 4.6 | *, openshift4/ose-logging-fluentd@sha256:7a064e87495743e9ca8aac591804faa80bae1d8cd6f6bf9621eaac8a92b44487_amd64 |
| Red Hat | openshift4/ose-sriov-operator-must-gather@sha256:485c7bca99d2a2e83601b0c53b2cbdaa4a65972f521114efb3b2c86a86666a3c_ppc64le as a component of Red Hat OpenShift Container Platform 4.6 | *, openshift4/ose-sriov-operator-must-gather@sha256:485c7bca99d2a2e83601b0c53b2cbdaa4a65972f521114efb3b2c86a86666a3c_ppc64le |
| Red Hat | openshift4/ose-node-feature-discovery@sha256:7c979a01b697d8bcaf9adf93cef6b9454bf9acf1e7c5fa5f7b236d8fad2f5336_ppc64le as a component of Red Hat OpenShift Container Platform 4.6 | *, openshift4/ose-node-feature-discovery@sha256:7c979a01b697d8bcaf9adf93cef6b9454bf9acf1e7c5fa5f7b236d8fad2f5336_ppc64le |
| Red Hat | openshift4/ose-sriov-dp-admission-controller@sha256:814dfd28c504879d0ab2368ea31b2871c868fcd482c06d8abf73e046dfab3ba7_ppc64le as a component of Red Hat OpenShift Container Platform 4.6 | openshift4/ose-sriov-dp-admission-controller@sha256:814dfd28c504879d0ab2368ea31b2871c868fcd482c06d8abf73e046dfab3ba7_ppc64le, * |
| Red Hat | openshift4/ose-elasticsearch-operator@sha256:e82702613ced53d2482405211bdd6751a0a07bb720ad504986f1b2b3c4b027df_s390x as a component of Red Hat OpenShift Container Platform 4.6 | *, openshift4/ose-elasticsearch-operator@sha256:e82702613ced53d2482405211bdd6751a0a07bb720ad504986f1b2b3c4b027df_s390x |
| Red Hat | openshift4/ose-ptp@sha256:8321ef62bb9da1a24ea345c030e307e6326fa1f7be759c12322c0fa719cea6ae_amd64 as a component of Red Hat OpenShift Container Platform 4.6 | *, openshift4/ose-ptp@sha256:8321ef62bb9da1a24ea345c030e307e6326fa1f7be759c12322c0fa719cea6ae_amd64 |
| Red Hat | openshift4/ose-elasticsearch-proxy@sha256:dca856b265c1b95dcea151b8367cf30b84c0d11df098f61a819d4f81e324d3f2_amd64 as a component of Red Hat OpenShift Container Platform 4.6 | *, openshift4/ose-elasticsearch-proxy@sha256:dca856b265c1b95dcea151b8367cf30b84c0d11df098f61a819d4f81e324d3f2_amd64 |
| Red Hat | openshift4/ose-logging-kibana6@sha256:8e2e9944c739b58cc9a01a5ca07c1db83d2a2ba4aee9453d97e0aa1f1f11bbbb_amd64 as a component of Red Hat OpenShift Container Platform 4.6 | *, * |
| Red Hat | openshift4/ose-cluster-nfd-operator@sha256:196e55ab840af28d507a1f6da9419ce874d4aa73c3c18a8d07ce3b2bf5ea275f_s390x as a component of Red Hat OpenShift Container Platform 4.6 | openshift4/ose-cluster-nfd-operator@sha256:196e55ab840af28d507a1f6da9419ce874d4aa73c3c18a8d07ce3b2bf5ea275f_s390x, * |
| Red Hat | openshift4/ose-logging-curator5@sha256:9eeebbf7be02555a153a50760a0a2c66ef2c210ec111bfaebaa830d94ac3d60b_ppc64le as a component of Red Hat OpenShift Container Platform 4.6 | *, openshift4/ose-logging-curator5@sha256:9eeebbf7be02555a153a50760a0a2c66ef2c210ec111bfaebaa830d94ac3d60b_ppc64le |
| Red Hat | openshift4/ose-sriov-network-config-daemon@sha256:9258fe2c89824fde2b55c00066c882f785385a1c194ba455924946fa077e3cf1_amd64 as a component of Red Hat OpenShift Container Platform 4.6 | *, * |
| Red Hat | openshift4/ose-sriov-network-device-plugin@sha256:ac2518a8f89a1ba77a44cf84e7a7096ef7cb3b3ea9fe2997c64e26503591635b_amd64 as a component of Red Hat OpenShift Container Platform 4.6 | *, openshift4/ose-sriov-network-device-plugin@sha256:ac2518a8f89a1ba77a44cf84e7a7096ef7cb3b3ea9fe2997c64e26503591635b_amd64 |
…and 106 more
Timeline
- May 4, 2022 CVE Published
- May 1, 2026 Distribution Patch
- May 1, 2026 Distribution Patch
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
- May 15, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2022:1622 advisory
- https://access.redhat.com/security/updates/classification/#moderate advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2059996 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2066837 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2022/rhsa-2022_1622.json advisory
- https://access.redhat.com/security/cve/CVE-2022-24769 advisory
- https://www.cve.org/CVERecord?id=CVE-2022-24769 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-24769 advisory
- https://github.com/moby/moby/security/advisories/GHSA-2mm7-x5h6-5pvq advisory