VDB
RHSA-2023%3A4671
RHSA-2023%3A4671
PUBLISHED
CVSS 7.300000190734863 HIGH
A flaw was found in containerd, where supplementary groups are not set up properly inside a container. If an attacker has direct access to a container and manipulates their supplementary group access, they may be able to use supplementary group access to bypass primary group restrictions in some cases. This issue can allow access to sensitive information or gain the ability to execute code in that container.
Risk Scores
CVSS 3.1
7.300000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | openshift4/ose-docker-builder@sha256:6fe59ab45153fd2f810e4866c6276cc2d2f0bb0ff6b8311ce75df99e6bb92577_ppc64le as a component of Red Hat OpenShift Container Platform 4.12 | *, openshift4/ose-docker-builder@sha256:6fe59ab45153fd2f810e4866c6276cc2d2f0bb0ff6b8311ce75df99e6bb92577_ppc64le, openshift4/ose-docker-builder@sha256:6fe59ab45153fd2f810e4866c6276cc2d2f0bb0ff6b8311ce75df99e6bb92577_ppc64le |
| Red Hat | openshift4/ose-tests@sha256:f534e7a95399d77c27d4a6e98e51f3d4e6a96014edf55561ef8eddec3db816e1_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | *, openshift4/ose-tests@sha256:f534e7a95399d77c27d4a6e98e51f3d4e6a96014edf55561ef8eddec3db816e1_amd64, openshift4/ose-tests@sha256:f534e7a95399d77c27d4a6e98e51f3d4e6a96014edf55561ef8eddec3db816e1_amd64 |
| Red Hat | openshift4/ose-tools-rhel8@sha256:b14bfb2e2b2c1c360775cc02cb7862578efa21a2f07f3660210b09054077eaf8_s390x as a component of Red Hat OpenShift Container Platform 4.12 | * |
| Red Hat | openshift4/ose-installer@sha256:0e743f9d5f8a45767bcf92cf6482e80d0f76f0463fef88ce14d08db058d4c522_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | * |
| Red Hat | openshift4/ose-operator-registry@sha256:d350fc56667fd380e943e2062ccbc5d62804503adf3009bcb25ba65c5c7fbca8_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-operator-registry@sha256:d350fc56667fd380e943e2062ccbc5d62804503adf3009bcb25ba65c5c7fbca8_amd64, openshift4/ose-operator-registry@sha256:d350fc56667fd380e943e2062ccbc5d62804503adf3009bcb25ba65c5c7fbca8_amd64, * |
| Red Hat | openshift4/ose-installer@sha256:e64da770e4db84e9c68d8fa40dbb7bee521a60c38cec77fa6ba0688a2d43c44b_arm64 as a component of Red Hat OpenShift Container Platform 4.12 | * |
| Red Hat | openshift4/ose-must-gather@sha256:cd2ffa9f221e44d8cf1fa927061f474ac81b085c20118c0844d68b41987b58aa_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-must-gather@sha256:cd2ffa9f221e44d8cf1fa927061f474ac81b085c20118c0844d68b41987b58aa_amd64, *, openshift4/ose-must-gather@sha256:cd2ffa9f221e44d8cf1fa927061f474ac81b085c20118c0844d68b41987b58aa_amd64 |
| Red Hat | openshift4/ose-console@sha256:bd0f127440401b36fc33585100e456b03dd9baa8511c6036f38714538923f441_s390x as a component of Red Hat OpenShift Container Platform 4.12 | *, openshift4/ose-console@sha256:bd0f127440401b36fc33585100e456b03dd9baa8511c6036f38714538923f441_s390x, openshift4/ose-console@sha256:bd0f127440401b36fc33585100e456b03dd9baa8511c6036f38714538923f441_s390x |
| Red Hat | openshift4/ose-operator-lifecycle-manager@sha256:b5b7254329899f3a0f3cd62c04f85f92ad8510796e9dd4afdef2dede4e7ba5d9_ppc64le as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-operator-lifecycle-manager@sha256:b5b7254329899f3a0f3cd62c04f85f92ad8510796e9dd4afdef2dede4e7ba5d9_ppc64le |
| Red Hat | openshift4/ose-tools-rhel8@sha256:bfd5a90cc1488cfb7f5c93cdabf335acda890bea76e1ccc7d5a3daa80095cb02_ppc64le as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-tools-rhel8@sha256:bfd5a90cc1488cfb7f5c93cdabf335acda890bea76e1ccc7d5a3daa80095cb02_ppc64le, openshift4/ose-tools-rhel8@sha256:bfd5a90cc1488cfb7f5c93cdabf335acda890bea76e1ccc7d5a3daa80095cb02_ppc64le, * |
| Red Hat | openshift4/ose-installer-artifacts@sha256:e08405e6518ea0027dd89d2ecee044d13d67a9a2f7eecb63795e5ec7c98c45a6_arm64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-installer-artifacts@sha256:e08405e6518ea0027dd89d2ecee044d13d67a9a2f7eecb63795e5ec7c98c45a6_arm64 |
| Red Hat | openshift4/ose-deployer@sha256:ab3cefbd3f6873dbf81f255d0403aeef3718fff840ebb68b12cc9c86ecb85791_arm64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-deployer@sha256:ab3cefbd3f6873dbf81f255d0403aeef3718fff840ebb68b12cc9c86ecb85791_arm64 |
| Red Hat | openshift4/network-tools-rhel8@sha256:21bf509f0936fbc30894ba6e06a4bc0182741f5bcedfc3d947ca344b2731b0aa_ppc64le as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/network-tools-rhel8@sha256:21bf509f0936fbc30894ba6e06a4bc0182741f5bcedfc3d947ca344b2731b0aa_ppc64le, *, * |
| Red Hat | openshift4/ose-baremetal-installer-rhel8@sha256:94d7d93d84e63db2ea61af785ea944e6119ebc1abdbe1078a89e5bb56e0e9dc8_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-baremetal-installer-rhel8@sha256:94d7d93d84e63db2ea61af785ea944e6119ebc1abdbe1078a89e5bb56e0e9dc8_amd64, openshift4/ose-baremetal-installer-rhel8@sha256:94d7d93d84e63db2ea61af785ea944e6119ebc1abdbe1078a89e5bb56e0e9dc8_amd64, * |
| Red Hat | openshift4/ose-cli-artifacts@sha256:f6d37eb88da116502ddfe1a98c4e867f5ce19007c16c6e1a03fdee79e5c7a4da_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-cli-artifacts@sha256:f6d37eb88da116502ddfe1a98c4e867f5ce19007c16c6e1a03fdee79e5c7a4da_amd64 |
| Red Hat | openshift4/ose-ovn-kubernetes-microshift-rhel8@sha256:e7bdcb4966ec262e02d21873b21fa348fb9545a9b4fc458d75cb94adcab61cc1_ppc64le as a component of Red Hat OpenShift Container Platform 4.12 | *, *, openshift4/ose-ovn-kubernetes-microshift-rhel8@sha256:e7bdcb4966ec262e02d21873b21fa348fb9545a9b4fc458d75cb94adcab61cc1_ppc64le |
| Red Hat | openshift4/ose-deployer@sha256:eebd86165f498e902e89160bc2515458fa8c874452e69d83dda653d5189b2d90_ppc64le as a component of Red Hat OpenShift Container Platform 4.12 | *, *, openshift4/ose-deployer@sha256:eebd86165f498e902e89160bc2515458fa8c874452e69d83dda653d5189b2d90_ppc64le |
| Red Hat | openshift4/ose-installer@sha256:0e743f9d5f8a45767bcf92cf6482e80d0f76f0463fef88ce14d08db058d4c522_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | *, openshift4/ose-installer@sha256:0e743f9d5f8a45767bcf92cf6482e80d0f76f0463fef88ce14d08db058d4c522_amd64, openshift4/ose-installer@sha256:0e743f9d5f8a45767bcf92cf6482e80d0f76f0463fef88ce14d08db058d4c522_amd64 |
| Red Hat | openshift4/ose-agent-installer-api-server-rhel8@sha256:b5c9fdabc4c9d9c54d544bcdba3de45a6c541468baf24d01839c6c1b32599da8_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-agent-installer-api-server-rhel8@sha256:b5c9fdabc4c9d9c54d544bcdba3de45a6c541468baf24d01839c6c1b32599da8_amd64 |
| Red Hat | openshift4/ose-tools-rhel8@sha256:bfd5a90cc1488cfb7f5c93cdabf335acda890bea76e1ccc7d5a3daa80095cb02_ppc64le as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-tools-rhel8@sha256:bfd5a90cc1488cfb7f5c93cdabf335acda890bea76e1ccc7d5a3daa80095cb02_ppc64le |
…and 138 more
Timeline
- Aug 23, 2023 CVE Published
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- May 15, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2023:4671 advisory
- https://access.redhat.com/security/updates/classification/#moderate advisory
- https://docs.openshift.com/container-platform/4.12/release_notes/ocp-4-12-release-notes.html advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2174485 issue
- https://issues.redhat.com/browse/OCPBUGS-14386 advisory
- https://issues.redhat.com/browse/OCPBUGS-16410 advisory
- https://issues.redhat.com/browse/OCPBUGS-16846 advisory
- https://issues.redhat.com/browse/OCPBUGS-17192 advisory
- https://issues.redhat.com/browse/OCPBUGS-17558 advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_4671.json advisory
- https://access.redhat.com/security/cve/CVE-2023-25173 advisory
- https://www.cve.org/CVERecord?id=CVE-2023-25173 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-25173 advisory
- https://github.com/containerd/containerd/commit/133f6bb6cd827ce35a5fb279c1ead12b9d21460a advisory
- https://github.com/containerd/containerd/releases/tag/v1.5.18 advisory
- https://github.com/containerd/containerd/releases/tag/v1.6.18 advisory
- https://github.com/containerd/containerd/security/advisories/GHSA-hmfx-3pcx-653p advisory
- https://www.benthamsgaze.org/2022/08/22/vulnerability-in-linux-containers-investigation-and-mitigation/ advisory