USN-5776-1
Dashboard / Vulnerabilities / USN-5776-1
USN-5776-1
Summary: containerd vulnerabilities
Details: It was discovered that containerd incorrectly handled memory when receiving certain faulty Exec or ExecSync commands. A remote attacker could possibly use this issue to cause a denial of service or crash containerd. (CVE-2022-23471, CVE-2022-31030) It was discovered that containerd incorrectly set up inheritable file capabilities. An attacker could possibly use this issue to escalate privileges inside a container. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2022-24769) It was discovered that containerd incorrectly handled access to encrypted container images when using imgcrypt library. A remote attacker could possibly use this issue to access encrypted images from other users. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2022-24778)
References: https://ubuntu.com/security/notices/USN-5776-1, https://ubuntu.com/security/CVE-2022-23471, https://ubuntu.com/security/CVE-2022-24769, https://ubuntu.com/security/CVE-2022-24778, https://ubuntu.com/security/CVE-2022-31030
Affected packages
Package
Name: containerd
Purl: pkg:deb/ubuntu/[email protected]~18.04.2?arch=source&distro=bionic
Affected ranges
Type: ECOSYSTEM
Events:
