CVE-2022-23648
Summary
| CVE | CVE-2022-23648 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-03-03 14:15:00 UTC |
| Updated | 2024-01-31 13:15:00 UTC |
| Description | containerd is a container runtime available as a daemon for Linux and Windows. A bug was found in containerd prior to versions 1.6.1, 1.5.10, and 1.14.12 where containers launched through containerd’s CRI implementation on Linux with a specially-crafted image configuration could gain access to read-only copies of arbitrary files and directories on the host. This may bypass any policy-based enforcement on container setup (including a Kubernetes Pod Security Policy) and expose potentially sensitive information. Kubernetes and crictl can both be configured to use containerd’s CRI implementation. This bug has been fixed in containerd 1.6.1, 1.5.10, and 1.4.12. Users should update to these versions to resolve the issue. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 11.0 | All | All | All |
| Operating System | Fedoraproject | Fedora | 34 | All | All | All |
| Operating System | Fedoraproject | Fedora | 35 | All | All | All |
| Operating System | Fedoraproject | Fedora | 36 | All | All | All |
| Application | Linuxfoundation | Containerd | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [SECURITY] Fedora 36 Update: containerd-1.6.1-1.fc36 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [SECURITY] Fedora 34 Update: containerd-1.6.1-1.fc34 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [SECURITY] Fedora 35 Update: containerd-1.6.1-1.fc35 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| containerd CRI plugin: Insecure handling of image volumes · Advisory · containerd/containerd · GitHub | CONFIRM | github.com | |
| Debian -- Security Information -- DSA-5091-1 containerd | DEBIAN | www.debian.org | |
| containerd Image Volume Insecure Handling ≈ Packet Storm | MISC | packetstormsecurity.com | |
| [SECURITY] Fedora 34 Update: containerd-1.6.1-1.fc34 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| Merge pull request #6607 from dmcgowan/prepare-v1.6.1 · containerd/containerd@10f428d · GitHub | MISC | github.com | |
| Release containerd 1.6.1 · containerd/containerd · GitHub | MISC | github.com | |
| Release containerd 1.4.13 · containerd/containerd · GitHub | MISC | github.com | |
| containerd: Multiple Vulnerabilities (GLSA 202401-31) — Gentoo security | security.gentoo.org | ||
| [SECURITY] Fedora 35 Update: containerd-1.6.1-1.fc35 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| Release containerd 1.5.10 · containerd/containerd · GitHub | MISC | github.com | |
| [SECURITY] Fedora 36 Update: containerd-1.6.1-1.fc36 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 179100 Debian Security Update for containerd (DSA 5091-1)
- 184412 Debian Security Update for containerd (CVE-2022-23648)
- 198688 Ubuntu Security Notification for containerd Vulnerability (USN-5311-1)
- 282510 Fedora Security Update for containerd (FEDORA-2022-230f2b024b)
- 282511 Fedora Security Update for containerd (FEDORA-2022-dc35dd101f)
- 353177 Amazon Linux Security Advisory for containerd : ALAS-2022-1568
- 353178 Amazon Linux Security Advisory for containerd : ALAS2NITRO-ENCLAVES-2022-015
- 353179 Amazon Linux Security Advisory for containerd : ALAS2DOCKER-2022-015
- 354449 Amazon Linux Security Advisory for containerd : ALAS2022-2022-032
- 354710 Amazon Linux Security Advisory for containerd : ALAS2022-2022-210
- 355261 Amazon Linux Security Advisory for containerd : ALAS2023-2023-079
- 355317 Amazon Linux Security Advisory for ecs-init, docker, containerd, runc : ALAS2ECS-2022-001
- 356884 Amazon Linux Security Advisory for containerd : ALAS2ECS-2023-024
- 502048 Alpine Linux Security Update for containerd
- 502258 Alpine Linux Security Update for containerd
- 504646 Alpine Linux Security Update for containerd
- 6140063 AWS Bottlerocket Security Update for containerd (GHSA-hmxq-qpgg-r69g)
- 671762 EulerOS Security Update for docker-engine (EulerOS-SA-2022-1825)
- 671766 EulerOS Security Update for docker-engine (EulerOS-SA-2022-1820)
- 671778 EulerOS Security Update for docker-engine (EulerOS-SA-2022-1836)
- 671822 EulerOS Security Update for docker-engine (EulerOS-SA-2022-1860)
- 673649 EulerOS Security Update for docker-engine (EulerOS-SA-2023-3118)
- 710846 Gentoo Linux containerd Multiple Vulnerabilities (GLSA 202401-31)
- 751817 OpenSUSE Security Update for containerd (openSUSE-SU-2022:0720-1)
- 752133 SUSE Enterprise Linux Security Update for containerd, docker (SUSE-SU-2022:1689-1)
- 753197 SUSE Enterprise Linux Security Update for containerd (SUSE-SU-2022:0720-1)
- 900731 Common Base Linux Mariner (CBL-Mariner) Security Update for moby-containerd (8882)