A flaw was found in crun where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers were started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs.
2022-04-04T20:15:10.940
2024-11-21T06:56:06.080
Modified
CVSSv3.1: 7.5 (HIGH)
AV:N/AC:M/Au:S/C:P/I:P/A:P
6.8
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | crun_project | crun | < 1.4.4 | Yes |
Operating System | fedoraproject | fedora | 34 | Yes |
Application | redhat | openshift_container_platform | 4.0 | Yes |
Operating System | redhat | enterprise_linux | 8.0 | Yes |