VDB

RHSA-2022%3A2265

RHSA-2022%3A2265 PUBLISHED CVSS 4.800000190734863 MEDIUM

A flaw was found in Moby (Docker Engine), where containers were started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs. Containers using Linux users and groups to perform privilege separation inside the container are most directly impacted.

Risk Scores

CVSS 3.1
4.800000190734863
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersions
Red Hatopenshift4/ose-local-storage-static-provisioner@sha256:2e4cd4911c431d35795fb9df99e2d8dec0b2a8f9c34b73635d6d4a2fa2c888b5_s390x as a component of Red Hat OpenShift Container Platform 4.6*, *
Red Hatopenshift4/ose-clusterresourceoverride-rhel8@sha256:9dedb87e0dc188fab70cf266af3ebe3a78440892abfdbf6d1b681787b9a27118_s390x as a component of Red Hat OpenShift Container Platform 4.6openshift4/ose-clusterresourceoverride-rhel8@sha256:9dedb87e0dc188fab70cf266af3ebe3a78440892abfdbf6d1b681787b9a27118_s390x, *
Red Hatopenshift4/ose-vertical-pod-autoscaler-rhel8@sha256:e3f42aeedcd26cbdc7c516f4bc1bc2308e4b215266b7119288fa08cfcacbabb4_amd64 as a component of Red Hat OpenShift Container Platform 4.6openshift4/ose-vertical-pod-autoscaler-rhel8@sha256:e3f42aeedcd26cbdc7c516f4bc1bc2308e4b215266b7119288fa08cfcacbabb4_amd64, *
Red Hatopenshift4/ose-sriov-operator-must-gather@sha256:6fe5acbb01c603ac1d3139679aea4cd1e101765a67335b46bee0c385d4ae3bce_s390x as a component of Red Hat OpenShift Container Platform 4.6openshift4/ose-sriov-operator-must-gather@sha256:6fe5acbb01c603ac1d3139679aea4cd1e101765a67335b46bee0c385d4ae3bce_s390x, *
Red Hatopenshift4/ose-jenkins-agent-nodejs-10-rhel8@sha256:8e6a828cbeb9aa83b7b6e49c32d0104c7d7b8a02107b807f433748582f8eda16_s390x as a component of Red Hat OpenShift Container Platform 4.6*, *
Red Hatopenshift4/ose-cluster-kube-descheduler-operator@sha256:20e244c5cd8db38b5563db339759d669923efd7b19f40f456b3d5d08c4446936_s390x as a component of Red Hat OpenShift Container Platform 4.6*, *
Red Hatopenshift4/ose-sriov-infiniband-cni@sha256:4ea347454d3a5684bee5f9d4e563010efa4b7a39d4d01a0b890db9f646385c24_ppc64le as a component of Red Hat OpenShift Container Platform 4.6*, openshift4/ose-sriov-infiniband-cni@sha256:4ea347454d3a5684bee5f9d4e563010efa4b7a39d4d01a0b890db9f646385c24_ppc64le
Red Hatopenshift4/ose-sriov-operator-must-gather@sha256:4e855fad1382fe683770830f8c454298cef2ce66d73204e1991799894210d6eb_amd64 as a component of Red Hat OpenShift Container Platform 4.6*, *
Red Hatopenshift4/ose-logging-kibana6@sha256:a1193e81711529a9d01c221be9494abcbe087e3ba101b918f74c7a444152289c_amd64 as a component of Red Hat OpenShift Container Platform 4.6*, openshift4/ose-logging-kibana6@sha256:a1193e81711529a9d01c221be9494abcbe087e3ba101b918f74c7a444152289c_amd64
Red Hatopenshift4/ose-egress-router@sha256:f0cdeba67fb4b5e87c4db1cfafe92d4691bbddfe9ee263561b8bb62427b4f2da_ppc64le as a component of Red Hat OpenShift Container Platform 4.6*, *
Red Hatopenshift4/ose-cluster-logging-operator@sha256:4aa140d30e2bfa23a2a84a913567827321edb954afd1419052749bd739287a68_s390x as a component of Red Hat OpenShift Container Platform 4.6*, *
Red Hatopenshift4/ose-metering-ansible-operator@sha256:20fe3ccab2dc32e9b39a1c07726c61f6178e2112f0e046159641e5ae6d0747fd_amd64 as a component of Red Hat OpenShift Container Platform 4.6*, openshift4/ose-metering-ansible-operator@sha256:20fe3ccab2dc32e9b39a1c07726c61f6178e2112f0e046159641e5ae6d0747fd_amd64
Red Hatopenshift4/ose-sriov-network-operator@sha256:89d579a9d211a6d11841b3b94dad15f82b5481a1067371dc459af48d945501d6_amd64 as a component of Red Hat OpenShift Container Platform 4.6openshift4/ose-sriov-network-operator@sha256:89d579a9d211a6d11841b3b94dad15f82b5481a1067371dc459af48d945501d6_amd64, *
Red Hatopenshift4/ose-egress-http-proxy@sha256:b1cc994c3fb61e33ec329e06db0a0640782de0b6815373896ce68d5fe9dd96b0_ppc64le as a component of Red Hat OpenShift Container Platform 4.6*, *
Red Hatopenshift4/ose-metering-reporting-operator@sha256:f3e7bb10e28822d9b2d765b3cda13a85edaac31dd6acac29f2622a428d28cefd_amd64 as a component of Red Hat OpenShift Container Platform 4.6*, openshift4/ose-metering-reporting-operator@sha256:f3e7bb10e28822d9b2d765b3cda13a85edaac31dd6acac29f2622a428d28cefd_amd64
Red Hatopenshift4/ose-service-idler-rhel8@sha256:831bf8f43ef249f9eaf3fc9e40af168d5d3ee963d81666be37781c4f7e3126a5_ppc64le as a component of Red Hat OpenShift Container Platform 4.6openshift4/ose-service-idler-rhel8@sha256:831bf8f43ef249f9eaf3fc9e40af168d5d3ee963d81666be37781c4f7e3126a5_ppc64le, *
Red Hatopenshift4/ose-elasticsearch-operator@sha256:2e02f8042ce7e14103be1e134a2fa68cbd2eff4b930f9e45ae695294c0e6770e_s390x as a component of Red Hat OpenShift Container Platform 4.6*, *
Red Hatopenshift4/ose-ptp-operator@sha256:0e6e0ce52b9147d3790b17fb5ee155f23c41282f07421cc102c6692966fb7546_s390x as a component of Red Hat OpenShift Container Platform 4.6*, *
Red Hatopenshift4/ose-vertical-pod-autoscaler-rhel8@sha256:9c70609b67570b325f27349e829351abf6062f1cac1ad8abc90f34d078216b0e_ppc64le as a component of Red Hat OpenShift Container Platform 4.6*, openshift4/ose-vertical-pod-autoscaler-rhel8@sha256:9c70609b67570b325f27349e829351abf6062f1cac1ad8abc90f34d078216b0e_ppc64le
Red Hatopenshift4/ose-local-storage-static-provisioner@sha256:8a70ceccc9073171686140978ef1b2cdaac61a74040f5bc28572e664387a249a_amd64 as a component of Red Hat OpenShift Container Platform 4.6*, openshift4/ose-local-storage-static-provisioner@sha256:8a70ceccc9073171686140978ef1b2cdaac61a74040f5bc28572e664387a249a_amd64

…and 106 more

Timeline

  • May 26, 2022 CVE Published
  • May 1, 2026 Distribution Patch
  • May 1, 2026 Distribution Patch
  • May 1, 2026 Security Advisory
  • May 1, 2026 Security Advisory
  • May 15, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›