CVE-2022-27651
Summary
| CVE | CVE-2022-27651 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-04-04 20:15:00 UTC |
| Updated | 2023-11-07 03:45:00 UTC |
| Description | A flaw was found in buildah where containers were incorrectly started with non-empty default permissions. A bug was found in Moby (Docker Engine) where containers were incorrectly started with non-empty inheritable Linux process capabilities, enabling an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs. This has the potential to impact confidentiality and integrity. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| do not set the inheritable capabilities · containers/buildah@e7e55c9 · GitHub |
MISC |
github.com |
|
| [SECURITY] Fedora 35 Update: buildah-1.23.3-2.fc35 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 36 Update: buildah-1.25.1-1.fc36 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 34 Update: buildah-1.23.3-1.fc34 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 35 Update: buildah-1.23.3-2.fc35 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| Default inheritable capabilities for linux container should be empty · Advisory · containers/buildah · GitHub |
MISC |
github.com |
|
| [SECURITY] Fedora 36 Update: buildah-1.25.1-1.fc36 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| 2066840 – (CVE-2022-27651) CVE-2022-27651 buildah: Default inheritable capabilities for linux container should be empty |
MISC |
bugzilla.redhat.com |
|
| [SECURITY] Fedora 34 Update: buildah-1.23.3-1.fc34 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159769 Oracle Enterprise Linux Security Update for container-tools:2.0 (ELSA-2022-1566)
- 159772 Oracle Enterprise Linux Security Update for container-tools:3.0 (ELSA-2022-1565)
- 159829 Oracle Enterprise Linux Security Update for container-tools:ol8 (ELSA-2022-1762)
- 182590 Debian Security Update for golang-github-containers-buildah (CVE-2022-27651)
- 240218 Red Hat Update for container-tools:2.0 (RHSA-2022:1407)
- 240238 Red Hat Update for container-tools:2.0 (RHSA-2022:1566)
- 240240 Red Hat Update for container-tools:3.0 (RHSA-2022:1565)
- 240293 Red Hat Update for container-tools:rhel8 security (RHSA-2022:1762)
- 240354 Red Hat Update for container-tools:2.0 (RHSA-2022:4651)
- 240387 Red Hat Update for container-tools:3.0 (RHSA-2022:4816)
- 282565 Fedora Security Update for buildah (FEDORA-2022-e6388650ea)
- 282566 Fedora Security Update for buildah (FEDORA-2022-224a93852c)
- 377411 Alibaba Cloud Linux Security Update for container-tools:3.0 (ALINUX3-SA-2022:0033)
- 502042 Alpine Linux Security Update for buildah
- 752641 SUSE Enterprise Linux Security Update for buildah (SUSE-SU-2022:3480-1)
- 753250 SUSE Enterprise Linux Security Update for buildah (SUSE-SU-2022:2680-1)
- 753474 SUSE Enterprise Linux Security Update for buildah (SUSE-SU-2022:1437-1)
- 901613 Common Base Linux Mariner (CBL-Mariner) Security Update for buildah (9318)
- 904600 Common Base Linux Mariner (CBL-Mariner) Security Update for buildah (11513)
- 905510 Common Base Linux Mariner (CBL-Mariner) Security Update for buildah (11513-1)
- 940486 AlmaLinux Security Update for container-tools:3.0 (ALSA-2022:1565)
- 940487 AlmaLinux Security Update for container-tools:2.0 (ALSA-2022:1566)
- 940562 AlmaLinux Security Update for container-tools:rhel8 (ALSA-2022:1762)
- 960194 Rocky Linux Security Update for container-tools:rhel8 (RLSA-2022:1762)
- 960216 Rocky Linux Security Update for container-tools:2.0 (RLSA-2022:1566)
- 960279 Rocky Linux Security Update for container-tools:3.0 (RLSA-2022:1565)