Oval Definition:oval:org.opensuse.security:def:20222989
Revision Date:2023-06-22Version:1
Title:CVE-2022-2989
Description:

An incorrect handling of the supplementary groups in the Podman container engine might lead to the sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to set access permissions and is able to execute a binary code in that container.
Family:unixClass:vulnerability
Status:Reference(s):Mitre CVE-2022-2989
SUSE CVE-2022-2989
SUSE-SU-2022:3819-1
SUSE-SU-2022:3820-1
SUSE-SU-2023:0187-1
SUSE-SU-2023:0326-1
Platform(s):SUSE Linux Enterprise High Performance Computing 15 SP5
SUSE Linux Enterprise Micro 5.3
SUSE Linux Enterprise Module for Containers 15 SP5
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server for SAP Applications 15 SP2
SUSE Linux Enterprise Server for SAP Applications 15 SP5
Product(s):
Definition Synopsis
  • SUSE Linux Enterprise Micro 5.3 is installed
  • AND Package Information
  • podman-4.3.1-150400.4.11.1 is installed
  • OR podman-cni-config-4.3.1-150400.4.11.1 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server for SAP Applications 15 SP2 is installed
  • AND Package Information
  • podman is affected
  • OR podman-cni-config is affected
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise High Performance Computing 15 SP5 is installed
  • OR SUSE Linux Enterprise Module for Containers 15 SP5 is installed
  • OR SUSE Linux Enterprise Server 15 SP5 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 15 SP5 is installed
  • AND Package Information
  • podman-4.4.4-150500.1.4 is installed
  • OR podman-cni-config-4.4.4-150500.1.4 is installed
  • OR podman-docker-4.4.4-150500.1.4 is installed
  • OR podman-remote-4.4.4-150500.1.4 is installed
  • BACK