Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2022-27650
Description:A flaw was found in crun where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers were started incorrectly with non- empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs.
Test IDs: 1.3.6.1.4.1.25623.1.0.820255   1.3.6.1.4.1.25623.1.1.10.2022.0141  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2022-27650
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HYIGABCZ7ZHAG2XCOGITTQRJU2ASWMFA/
https://bugzilla.redhat.com/show_bug.cgi?id=2066845
https://bugzilla.redhat.com/show_bug.cgi?id=2066845
https://github.com/containers/crun/commit/1aeeed2e4fdeffb4875c0d0b439915894594c8c6
https://github.com/containers/crun/commit/1aeeed2e4fdeffb4875c0d0b439915894594c8c6
https://github.com/containers/crun/security/advisories/GHSA-wr4f-w546-m398
https://github.com/containers/crun/security/advisories/GHSA-wr4f-w546-m398




© 1998-2025 E-Soft Inc. All rights reserved.