Oval Definition:oval:org.opensuse.security:def:202227650
Revision Date:2022-06-30Version:1
Title:CVE-2022-27650
Description:

A flaw was found in crun where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers were started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs.
Family:unixClass:vulnerability
Status:Reference(s):Mitre CVE-2022-27650
SUSE CVE-2022-27650
Platform(s):openSUSE Tumbleweed
Product(s):
Definition Synopsis
  • openSUSE Tumbleweed is installed
  • AND crun-1.4.4-1.1 is installed
  • BACK