VDB
RHSA-2023:4025
RHSA-2023:4025
PUBLISHED
CVSS 7.300000190734863 HIGH
A flaw was found in containerd, where supplementary groups are not set up properly inside a container. If an attacker has direct access to a container and manipulates their supplementary group access, they may be able to use supplementary group access to bypass primary group restrictions in some cases. This issue can allow access to sensitive information or gain the ability to execute code in that container.
Risk Scores
CVSS 3.1
7.300000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | openshift4-wincw/windows-machine-config-operator-bundle@sha256:5623b1b97c1423e31ba92d1fcf5bc73a90d7a08a08c941b883c139035deeb7c5_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4-wincw/windows-machine-config-operator-bundle@sha256:5623b1b97c1423e31ba92d1fcf5bc73a90d7a08a08c941b883c139035deeb7c5_amd64 |
| Red Hat | openshift4-wincw/windows-machine-config-rhel8-operator@sha256:7057aa220818c452c1edfbe8d049a74807ee24162e32f1ffe2e5116e9b508336_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | * |
| Red Hat | openshift4-wincw/windows-machine-config-operator-bundle@sha256:5623b1b97c1423e31ba92d1fcf5bc73a90d7a08a08c941b883c139035deeb7c5_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | *, *, openshift4-wincw/windows-machine-config-operator-bundle@sha256:5623b1b97c1423e31ba92d1fcf5bc73a90d7a08a08c941b883c139035deeb7c5_amd64 |
| Red Hat | openshift4-wincw/windows-machine-config-rhel8-operator@sha256:7057aa220818c452c1edfbe8d049a74807ee24162e32f1ffe2e5116e9b508336_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4-wincw/windows-machine-config-rhel8-operator@sha256:7057aa220818c452c1edfbe8d049a74807ee24162e32f1ffe2e5116e9b508336_amd64, openshift4-wincw/windows-machine-config-rhel8-operator@sha256:7057aa220818c452c1edfbe8d049a74807ee24162e32f1ffe2e5116e9b508336_amd64, * |
Timeline
- Jul 18, 2023 CVE Published
- May 1, 2026 Security Advisory
- May 5, 2026 Distribution Patch
- May 15, 2026 CVE Updated
- May 15, 2026 Distribution Patch
- May 15, 2026 Security Advisory
References
- https://issues.redhat.com/browse/OCPBUGS-10935 advisory
- https://issues.redhat.com/browse/OCPBUGS-13790 advisory
- https://issues.redhat.com/browse/OCPBUGS-14260 advisory
- https://issues.redhat.com/browse/OCPBUGS-14445 advisory
- https://issues.redhat.com/browse/OCPBUGS-8085 advisory
- https://access.redhat.com/security/cve/CVE-2023-25173 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-25173 advisory
- https://issues.redhat.com/browse/OCPBUGS-10417 advisory
- https://issues.redhat.com/browse/OCPBUGS-10784 advisory
- https://issues.redhat.com/browse/OCPBUGS-4862 advisory
- https://issues.redhat.com/browse/OCPBUGS-8056 advisory
- https://issues.redhat.com/browse/WINC-1037 advisory
- https://www.benthamsgaze.org/2022/08/22/vulnerability-in-linux-containers-investigation-and-mitigation/ advisory
- https://access.redhat.com/security/updates/classification/#low advisory
- https://issues.redhat.com/browse/OCPBUGS-7336 advisory
- https://issues.redhat.com/browse/WINC-981 advisory
- https://issues.redhat.com/browse/WINC-983 advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_4025.json advisory
- https://github.com/containerd/containerd/releases/tag/v1.6.18 advisory
- https://access.redhat.com/errata/RHSA-2023:4025 advisory
…and 10 more