UBUNTU-CVE-2022-27649
Dashboard / Vulnerabilities / UBUNTU-CVE-2022-27649
Summary:
Details: A flaw was found in Podman, where containers were started incorrectly with non-empty default permissions. A vulnerability was found in Moby (Docker Engine), where containers were started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs.
References: https://ubuntu.com/security/CVE-2022-27649, https://github.com/containers/podman/releases/tag/v4.0.3, https://github.com/containers/podman/commit/aafa80918a245edcbdaceb1191d749570f1872d0, https://github.com/containers/podman/commit/7b368768c2990b9781b2b6813e1c7f91c7e6cb13, https://bugzilla.redhat.com/show_bug.cgi?id=2066568, https://github.com/containers/podman/security/advisories/GHSA-qvf8-p83w-v58j, https://github.com/containers/podman/commit/aafa80918a245edcbdaceb1191d749570f1872d0, https://www.cve.org/CVERecord?id=CVE-2022-27649
Affected packages
Package
Name: libpod
Purl: pkg:deb/ubuntu/[email protected]+ds1-1ubuntu1.22.04.3+esm3?arch=source&distro=esm-apps/jammy
Affected ranges
Type: ECOSYSTEM
Events:
