GHSA-c3g4-w6cv-6v7h

    Dashboard / Vulnerabilities / GHSA-c3g4-w6cv-6v7h

    GHSA-c3g4-w6cv-6v7h

    Published: 1 Apr 2022Last Modified: 10 Sept 2026

    Summary: Non-empty default inheritable capabilities for linux container in Buildah

    Details: A bug was found in Buildah where containers were created with non-empty inheritable Linux process capabilities, creating an atypical Linux environment and enabling programs with inheritable file capabilities to elevate those capabilities to the permitted set during execve(2). This bug did not affect the container security sandbox as the inheritable set never contained more capabilities than were included in the container's bounding set.

    Affected packages

    Package

    Name: github.com/containers/buildah

    Purl: pkg:golang/github.com/containers/buildah

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -1.25.0

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-c3g4-w6cv-6v7h | CVE-DB