A flaw was found in Podman, where containers were started incorrectly with non-empty default permissions. A vulnerability was found in Moby (Docker Engine), where containers were started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2022-04-04T19:45:43

Updated: 2022-05-14T02:06:11

Reserved: 2022-03-22T00:00:00


Link: CVE-2022-27649

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2022-04-04T20:15:10.890

Modified: 2023-11-07T03:45:22.360


Link: CVE-2022-27649

JSON object: View

cve-icon Redhat Information

No data.

CWE