Candidate: CVE-2022-27650 PublicDate: 2022-04-04 20:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-27650 https://github.com/containers/crun/commit/b847d146d496c9d7beba166fd595488e85488562 (1.4.4) https://bugzilla.redhat.com/show_bug.cgi?id=2066845 https://github.com/containers/crun/commit/1aeeed2e4fdeffb4875c0d0b439915894594c8c6 https://github.com/containers/crun/security/advisories/GHSA-wr4f-w546-m398 Description: A flaw was found in crun where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers were started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs. Ubuntu-Description: Notes: Mitigation: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H [7.5 HIGH] Patches_crun: upstream_crun: needs-triage trusty_crun: ignored (out of standard support) xenial_crun: ignored (out of standard support) focal_crun: needs-triage impish_crun: needs-triage jammy_crun: needs-triage devel_crun: needs-triage