CVE-2022-1227
Summary
| CVE | CVE-2022-1227 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-04-29 16:15:00 UTC |
| Updated | 2023-11-07 03:41:00 UTC |
| Description | A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is downloaded by a potential victim, the vulnerability is triggered after a user runs the 'podman top' command. This action gives the attacker access to the host filesystem, leading to information disclosure or denial of service. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| podman top not work with userns=keep-id container · Issue #10941 · containers/podman · GitHub |
MISC |
github.com |
|
| [SECURITY] Fedora 34 Update: podman-3.4.7-1.fc34 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 34 Update: podman-3.4.7-1.fc34 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| 2070368 – (CVE-2022-1227) CVE-2022-1227 psgo: Privilege escalation in 'podman top' |
MISC |
bugzilla.redhat.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159829 Oracle Enterprise Linux Security Update for container-tools:ol8 (ELSA-2022-1762)
- 159840 Oracle Enterprise Linux Security Update for container-tools:3.0 (ELSA-2022-2143)
- 183544 Debian Security Update for libpodgolang-github-containers-psgo (CVE-2022-1227)
- 240288 Red Hat Update for container-tools:3.0 (RHSA-2022:2143)
- 240293 Red Hat Update for container-tools:rhel8 security (RHSA-2022:1762)
- 240325 Red Hat Update for podman (RHSA-2022:2190)
- 240354 Red Hat Update for container-tools:2.0 (RHSA-2022:4651)
- 240364 Red Hat OpenShift Container Platform 4.6 Security Update (RHSA-2022:2263)
- 240387 Red Hat Update for container-tools:3.0 (RHSA-2022:4816)
- 240552 Red Hat Update for container-tools:rhel8 (RHSA-2022:5622)
- 282608 Fedora Security Update for podman (FEDORA-2022-932d07be95)
- 282631 Fedora Security Update for podman (FEDORA-2022-c87047f163)
- 282683 Fedora Security Update for podman (FEDORA-2022-5e637f6cc6)
- 502157 Alpine Linux Security Update for podman
- 753361 SUSE Enterprise Linux Security Update for podman (SUSE-SU-2022:2834-1)
- 753444 SUSE Enterprise Linux Security Update for podman (SUSE-SU-2022:2839-1)
- 770153 Red Hat OpenShift Container Platform 4.6 Security Update (RHSA-2022:2263)
- 901609 Common Base Linux Mariner (CBL-Mariner) Security Update for podman (9656)
- 902618 Common Base Linux Mariner (CBL-Mariner) Security Update for podman (9656-1)
- 940556 AlmaLinux Security Update for container-tools:3.0 (ALSA-2022:2143)
- 940562 AlmaLinux Security Update for container-tools:rhel8 (ALSA-2022:1762)
- 960194 Rocky Linux Security Update for container-tools:rhel8 (RLSA-2022:1762)
- 960445 Rocky Linux Security Update for container-tools:3.0 (RLSA-2022:2143)