Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Mageia 8 MGASA-2022-0192 Critical: Opencontainers-Runc Exec Process Bug

mageia
Calendar Grey May 21, 2022
Dist Mageia Esm H88
The latest release of Opencontainers-runc tackles a severe flaw that poses risks of privilege escalation. Ensure you upgrade your systems without delay.
A bug was found in runc where runc exec --cap executed processes with non-empty inheritable Linux process capabilities, creating an atypical Linux environment and enabling programs...

Summary

A bug was found in runc where runc exec --cap executed processes with non-empty inheritable Linux process capabilities, creating an atypical Linux environment and enabling programs with inheritable file capabilities to elevate those capabilities to the permitted set during execve(2). This bug did not affect the container security sandbox as the inheritable set never contained more capabilities than were included in the container's bounding set. (CVE-2022-29162)

References

- https://bugs.mageia.org/show_bug.cgi?id=30421

- https://github.com/opencontainers/runc/security/advisories/GHSA-f3fp-gc8g-vw66

- https://www.openwall.com/lists/oss-security/2022/05/12/1

- https://www.cve.org/CVERecord?id=CVE-2022-29162

Resolution

SRPMS

- 8/core/opencontainers-runc-1.1.2-2.mga8

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 21 May 2022
URL: https://advisories.mageia.org/MGASA-2022-0192.html
Type: security
CVE: CVE-2022-29162

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here