Beveiligingsadvies

CVE-2022-27650

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2022-04-04 19:45:45
Laatst bijgewerkt 2024-08-03 05:32:59
Toegewezen door redhat
CVSS-score geen score
Status PUBLISHED

Beschrijving

A flaw was found in crun where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers were started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs.