Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 839363 (CVE-2022-27652) - <app-containers/cri-o-1.24.0: containers started with non-empty capabilites
Summary: <app-containers/cri-o-1.24.0: containers started with non-empty capabilites
Status: RESOLVED FIXED
Alias: CVE-2022-27652
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL: https://github.com/cri-o/cri-o/securi...
Whiteboard: ~4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2022-04-19 02:10 UTC by John Helmert III
Modified: 2022-06-06 19:45 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-04-19 02:10:52 UTC
CVE-2022-27652:

A flaw was found in cri-o, where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs.

This will be fixed in 1.24.0.
Comment 1 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-06-06 19:45:55 UTC
Done since May 15:

commit 1f78fbda4dc56ba0af4d327a21de7c4e8b4d1c6f
Author: Zac Medico <zmedico@gentoo.org>
Date:   Sun May 15 20:29:21 2022 -0700

    app-containers/cri-o: drop 1.23.2

    Closes: https://bugs.gentoo.org/844292
    Signed-off-by: Zac Medico <zmedico@gentoo.org>

 delete mode 100644 app-containers/cri-o/cri-o-1.23.2.ebuild