CVE-2022-27652

MEDIUM

cri-o < 1.24.0 - Incorrect Default Permissions

Title source: llm
STIX 2.1

Description

A flaw was found in cri-o, where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs.

References (2)

Core 2
Core References
Issue Tracking, Third Party Advisory x_refsource_misc
https://bugzilla.redhat.com/show_bug.cgi?id=2066839
Mitigation, Third Party Advisory x_refsource_misc
https://github.com/cri-o/cri-o/security/advisories/GHSA-4hj2-r2pm-3hc6

Scores

CVSS v3 5.3
EPSS 0.0002
EPSS Percentile 6.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Details

CWE
CWE-276
Status published
Products (6)
cri-o/cri-o 0 - 1.24.0Go
fedoraproject/fedora 35
kubernetes/cri-o
mobyproject/moby < 20.10.14
redhat/openshift_container_platform 3.11
redhat/openshift_container_platform 4.0
Published Apr 18, 2022
Tracked Since Feb 18, 2026