CVE-2022-2989: An incorrect handling of the supplementary groups in the Podman container engine might lead to the sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to set access permissions and is able to execute a binary code in that container. The RedHat bug has no reference to upstream: https://bugzilla.redhat.com/show_bug.cgi?id=2121445
(In reply to John Helmert III from comment #0) > CVE-2022-2989: > > An incorrect handling of the supplementary groups in the Podman container > engine might lead to the sensitive information disclosure or possible data > modification if an attacker has direct access to the affected container > where supplementary groups are used to set access permissions and is able to > execute a binary code in that container. > > The RedHat bug has no reference to upstream: > https://bugzilla.redhat.com/show_bug.cgi?id=2121445 Now there is! Unreleased patch is: https://github.com/containers/podman/commit/5c7f28336171f0a5137edd274e45608120d31289
(In reply to John Helmert III from comment #1) > (In reply to John Helmert III from comment #0) > > CVE-2022-2989: > > > > An incorrect handling of the supplementary groups in the Podman container > > engine might lead to the sensitive information disclosure or possible data > > modification if an attacker has direct access to the affected container > > where supplementary groups are used to set access permissions and is able to > > execute a binary code in that container. > > > > The RedHat bug has no reference to upstream: > > https://bugzilla.redhat.com/show_bug.cgi?id=2121445 > > Now there is! Unreleased patch is: > https://github.com/containers/podman/commit/ > 5c7f28336171f0a5137edd274e45608120d31289 In v4.3.0-rc1
And now in 4.3.0. Please bump.
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=6e114cc38eb7cb4d434e366d6fff10281b483827 commit 6e114cc38eb7cb4d434e366d6fff10281b483827 Author: Zac Medico <zmedico@gentoo.org> AuthorDate: 2022-10-20 00:02:49 +0000 Commit: Zac Medico <zmedico@gentoo.org> CommitDate: 2022-10-20 00:02:57 +0000 app-containers/podman: add 4.3.0 Bug: https://bugs.gentoo.org/870931 Signed-off-by: Zac Medico <zmedico@gentoo.org> app-containers/podman/Manifest | 1 + app-containers/podman/podman-4.3.0.ebuild | 165 ++++++++++++++++++++++++++++++ 2 files changed, 166 insertions(+)
Thank you! Please stabilize when ready.
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=c4ed032cdd4aff2e5e517f0f380d2587fc53e81a commit c4ed032cdd4aff2e5e517f0f380d2587fc53e81a Author: Zac Medico <zmedico@gentoo.org> AuthorDate: 2023-01-06 22:33:27 +0000 Commit: Zac Medico <zmedico@gentoo.org> CommitDate: 2023-01-06 22:33:46 +0000 app-containers/podman: drop 4.1.0-r1, 4.2.1, 4.3.0 Bug: https://bugs.gentoo.org/870931 Signed-off-by: Zac Medico <zmedico@gentoo.org> app-containers/podman/Manifest | 3 - app-containers/podman/podman-4.1.0-r1.ebuild | 165 --------------------------- app-containers/podman/podman-4.2.1.ebuild | 165 --------------------------- app-containers/podman/podman-4.3.0.ebuild | 165 --------------------------- 4 files changed, 498 deletions(-)
Thanks!
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/data/glsa.git/commit/?id=3671dbb8919b2952a3de8b9a51e7573f2b16d234 commit 3671dbb8919b2952a3de8b9a51e7573f2b16d234 Author: GLSAMaker <glsamaker@gentoo.org> AuthorDate: 2024-07-05 07:05:25 +0000 Commit: Hans de Graaff <graaff@gentoo.org> CommitDate: 2024-07-05 07:06:00 +0000 [ GLSA 202407-12 ] podman: Multiple Vulnerabilities Bug: https://bugs.gentoo.org/829896 Bug: https://bugs.gentoo.org/870931 Bug: https://bugs.gentoo.org/896372 Bug: https://bugs.gentoo.org/921290 Bug: https://bugs.gentoo.org/923751 Bug: https://bugs.gentoo.org/927500 Bug: https://bugs.gentoo.org/927501 Signed-off-by: GLSAMaker <glsamaker@gentoo.org> Signed-off-by: Hans de Graaff <graaff@gentoo.org> glsa-202407-12.xml | 56 ++++++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 56 insertions(+)