Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Mageia 8 MGASA-2022-0088 Moderate: Docker-Containerd Access Issue

mageia
Calendar Grey March 6, 2022
Dist Mageia Esm H88
Mageia has released a security patch: docker-containerd fixes a vulnerability that could lead to unauthorized file access from within containers. Explore the specifics.
A bug was found in containerd where containers launched through containerd’s CRI implementation with a specially-crafted image configuration could gain access to read-only copies...

Summary

A bug was found in containerd where containers launched through containerd’s CRI implementation with a specially-crafted image configuration could gain access to read-only copies of arbitrary files and directories on the host. This may bypass any policy-based enforcement on container setup (including a Kubernetes Pod Security Policy) and expose potentially sensitive information. Kubernetes and crictl can both be configured to use containerd’s CRI implementation. (CVE-2022-23648)

References

- https://bugs.mageia.org/show_bug.cgi?id=30111

- https://github.com/containerd/containerd/security/advisories/GHSA-crp2-qrr5-8pq7

- https://ubuntu.com/security/notices/USN-5311-1

- https://www.cve.org/CVERecord?id=CVE-2022-23648

Resolution

SRPMS

- 8/core/docker-containerd-1.5.10-1.mga8

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 06 Mar 2022
URL: https://advisories.mageia.org/MGASA-2022-0088.html
Type: security
CVE: CVE-2022-23648

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here