{"api_version":"1","generated_at":"2026-07-23T13:49:23+00:00","cve":"CVE-2022-31214","urls":{"html":"https://cve.report/CVE-2022-31214","api":"https://cve.report/api/cve/CVE-2022-31214.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2022-31214","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2022-31214"},"summary":{"title":"CVE-2022-31214","description":"A Privilege Context Switching issue was discovered in join.c in Firejail 0.9.68. By crafting a bogus Firejail container that is accepted by the Firejail setuid-root program as a join target, a local attacker can enter an environment in which the Linux user namespace is still the initial user namespace, the NO_NEW_PRIVS prctl is not activated, and the entered mount namespace is under the attacker's control. In this way, the filesystem layout can be adjusted to gain root privileges through execution of available setuid-root binaries such as su or sudo.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2022-06-09 16:15:00","updated_at":"2023-11-07 03:47:00"},"problem_types":["CWE-269"],"metrics":[],"references":[{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6RZOTZ36RUSL6DOVHITY25ZYKWTG5HN3/","name":"FEDORA-2022-827d9ce8ac","refsource":"FEDORA","tags":[],"title":"[SECURITY] Fedora 35 Update: firejail-0.9.70-1.fc35 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KUZZ5M6LIBYRKTKGROXC47TDC3FRTGJF/","name":"FEDORA-2022-e8e9b50a33","refsource":"FEDORA","tags":[],"title":"[SECURITY] Fedora 36 Update: firejail-0.9.70-1.fc36 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://firejail.wordpress.com/download-2/release-notes/","name":"https://firejail.wordpress.com/download-2/release-notes/","refsource":"MISC","tags":[],"title":"Release Notes | Firejail","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.openwall.com/lists/oss-security/2022/06/08/10","name":"https://www.openwall.com/lists/oss-security/2022/06/08/10","refsource":"MISC","tags":[],"title":"oss-security - firejail: local root exploit reachable via --join logic\n (CVE-2022-31214)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SIBEBE3KFINMGJATBQQS7D2VQQ62ZVMF/","name":"FEDORA-2022-7ecd36b131","refsource":"FEDORA","tags":[],"title":"[SECURITY] Fedora 37 Update: firejail-0.9.70-1.fc37 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://lists.debian.org/debian-lts-announce/2022/06/msg00023.html","name":"[debian-lts-announce] 20220629 [SECURITY] [DLA 3061-1] firejail security update","refsource":"MLIST","tags":[],"title":"[SECURITY] [DLA 3061-1] firejail security update","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6RZOTZ36RUSL6DOVHITY25ZYKWTG5HN3/","name":"FEDORA-2022-827d9ce8ac","refsource":"","tags":[],"title":"[SECURITY] Fedora 35 Update: firejail-0.9.70-1.fc35 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SIBEBE3KFINMGJATBQQS7D2VQQ62ZVMF/","name":"FEDORA-2022-7ecd36b131","refsource":"","tags":[],"title":"[SECURITY] Fedora 37 Update: firejail-0.9.70-1.fc37 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KUZZ5M6LIBYRKTKGROXC47TDC3FRTGJF/","name":"FEDORA-2022-e8e9b50a33","refsource":"","tags":[],"title":"[SECURITY] Fedora 36 Update: firejail-0.9.70-1.fc36 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://security.gentoo.org/glsa/202305-19","name":"GLSA-202305-19","refsource":"GENTOO","tags":[],"title":"Firejail: Local Privilege Escalation (GLSA 202305-19) — Gentoo security","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.debian.org/security/2022/dsa-5167","name":"DSA-5167","refsource":"DEBIAN","tags":[],"title":"Debian -- Security Information -- DSA-5167-1 firejail","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2022-31214","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2022-31214","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2022","cve_id":"31214","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"debian","cpe5":"debian_linux","cpe6":"10.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2022","cve_id":"31214","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"debian","cpe5":"debian_linux","cpe6":"9.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2022","cve_id":"31214","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"fedoraproject","cpe5":"fedora","cpe6":"35","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2022","cve_id":"31214","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"fedoraproject","cpe5":"fedora","cpe6":"36","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2022","cve_id":"31214","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"fedoraproject","cpe5":"fedora","cpe6":"37","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2022","cve_id":"31214","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"firejail_project","cpe5":"firejail","cpe6":"0.9.68","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2022-31214","qid":"179487","title":"Debian Security Update for firejail (DSA 5167-1)"},{"cve":"CVE-2022-31214","qid":"179974","title":"Debian Security Update for firejail (DLA 3061-1)"},{"cve":"CVE-2022-31214","qid":"183458","title":"Debian Security Update for firejail (CVE-2022-31214)"},{"cve":"CVE-2022-31214","qid":"283117","title":"Fedora Security Update for firejail (FEDORA-2022-e8e9b50a33)"},{"cve":"CVE-2022-31214","qid":"283118","title":"Fedora Security Update for firejail (FEDORA-2022-827d9ce8ac)"},{"cve":"CVE-2022-31214","qid":"710724","title":"Gentoo Linux Firejail Local Privilege Escalation Vulnerability (GLSA 202305-19)"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2022-31214","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"A Privilege Context Switching issue was discovered in join.c in Firejail 0.9.68. By crafting a bogus Firejail container that is accepted by the Firejail setuid-root program as a join target, a local attacker can enter an environment in which the Linux user namespace is still the initial user namespace, the NO_NEW_PRIVS prctl is not activated, and the entered mount namespace is under the attacker's control. In this way, the filesystem layout can be adjusted to gain root privileges through execution of available setuid-root binaries such as su or sudo."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://firejail.wordpress.com/download-2/release-notes/","refsource":"MISC","name":"https://firejail.wordpress.com/download-2/release-notes/"},{"refsource":"MISC","name":"https://www.openwall.com/lists/oss-security/2022/06/08/10","url":"https://www.openwall.com/lists/oss-security/2022/06/08/10"},{"refsource":"DEBIAN","name":"DSA-5167","url":"https://www.debian.org/security/2022/dsa-5167"},{"refsource":"MLIST","name":"[debian-lts-announce] 20220629 [SECURITY] [DLA 3061-1] firejail security update","url":"https://lists.debian.org/debian-lts-announce/2022/06/msg00023.html"},{"refsource":"FEDORA","name":"FEDORA-2022-7ecd36b131","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SIBEBE3KFINMGJATBQQS7D2VQQ62ZVMF/"},{"refsource":"FEDORA","name":"FEDORA-2022-e8e9b50a33","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KUZZ5M6LIBYRKTKGROXC47TDC3FRTGJF/"},{"refsource":"FEDORA","name":"FEDORA-2022-827d9ce8ac","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6RZOTZ36RUSL6DOVHITY25ZYKWTG5HN3/"},{"refsource":"GENTOO","name":"GLSA-202305-19","url":"https://security.gentoo.org/glsa/202305-19"}]}},"nvd":{"publishedDate":"2022-06-09 16:15:00","lastModifiedDate":"2023-11-07 03:47:00","problem_types":["CWE-269"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE","baseScore":7.2},"severity":"HIGH","exploitabilityScore":3.9,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:firejail_project:firejail:0.9.68:*:*:*:*:*:*:*","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":null,"notes":[]}}}