Vulnerability Name:

CVE-2022-23648 (CCN-220823)

Assigned:2022-03-02
Published:2022-03-02
Updated:2022-04-25
Summary:containerd is a container runtime available as a daemon for Linux and Windows. A bug was found in containerd prior to versions 1.6.1, 1.5.10, and 1.14.12 where containers launched through containerd’s CRI implementation on Linux with a specially-crafted image configuration could gain access to read-only copies of arbitrary files and directories on the host. This may bypass any policy-based enforcement on container setup (including a Kubernetes Pod Security Policy) and expose potentially sensitive information. Kubernetes and crictl can both be configured to use containerd’s CRI implementation. This bug has been fixed in containerd 1.6.1, 1.5.10, and 1.4.12. Users should update to these versions to resolve the issue.
CVSS v3 Severity:7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
6.7 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:P/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): None
Availibility (A): None
7.5 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
6.7 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:P/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
7.8 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-200
Vulnerability Consequences:Obtain Information
References:Source: MITRE
Type: CNA
CVE-2022-23648

Source: MISC
Type: Exploit, Third Party Advisory
http://packetstormsecurity.com/files/166421/containerd-Image-Volume-Insecure-Handling.html

Source: XF
Type: UNKNOWN
containerd-cve202223648-info-disc(220823)

Source: MISC
Type: Patch, Third Party Advisory
https://github.com/containerd/containerd/commit/10f428dac7cec44c864e1b830a4623af27a9fc70

Source: MISC
Type: Patch, Release Notes, Third Party Advisory
https://github.com/containerd/containerd/releases/tag/v1.4.13

Source: MISC
Type: Patch, Release Notes, Third Party Advisory
https://github.com/containerd/containerd/releases/tag/v1.5.10

Source: MISC
Type: Patch, Release Notes, Third Party Advisory
https://github.com/containerd/containerd/releases/tag/v1.6.1

Source: CCN
Type: containerd GIT Repository
containerd CRI plugin: Insecure handling of image volumes

Source: CONFIRM
Type: Third Party Advisory
https://github.com/containerd/containerd/security/advisories/GHSA-crp2-qrr5-8pq7

Source: FEDORA
Type: Issue Tracking, Third Party Advisory
FEDORA-2022-230f2b024b

Source: FEDORA
Type: Issue Tracking, Third Party Advisory
FEDORA-2022-d9c9bf56f6

Source: FEDORA
Type: Issue Tracking, Third Party Advisory
FEDORA-2022-dc35dd101f

Source: CCN
Type: Packet Storm Security [03-24-2022]
containerd Image Volume Insecure Handling

Source: CCN
Type: oss-sec Mailing List, Wed, 2 Mar 2022 19:17:44 +0000
CVE-2022-23648: containerd CRI plugin: Insecure handling of image volumes

Source: DEBIAN
Type: Mailing List, Third Party Advisory
DSA-5091

Source: CCN
Type: IBM Security Bulletin 6615221 (Robotic Process Automation for Cloud Pak)
Multiple Security Vulnerabilities may affect IBM Robotic Process Automation for Cloud Pak

Source: CCN
Type: IBM Security Bulletin 6830587 (MQ Operator)
IBM MQ Operator and Queue manager container images are vulnerable to multiple vulnerabilities from containerd, gnupg2, runc and IBM WebSphere Application Server Liberty

Vulnerable Configuration:Configuration 1:
  • cpe:/a:linuxfoundation:containerd:*:*:*:*:*:*:*:* (Version < 1.4.13)
  • OR cpe:/a:linuxfoundation:containerd:*:*:*:*:*:*:*:* (Version >= 1.5.0 and < 1.5.10)
  • OR cpe:/a:linuxfoundation:containerd:*:*:*:*:*:*:*:* (Version >= 1.6.0 and < 1.6.1)

  • Configuration 2:
  • cpe:/o:debian:debian_linux:11.0:*:*:*:*:*:*:*
  • OR cpe:/o:fedoraproject:fedora:34:*:*:*:*:*:*:*
  • OR cpe:/o:fedoraproject:fedora:35:*:*:*:*:*:*:*
  • OR cpe:/o:fedoraproject:fedora:36:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:linuxfoundation:containerd:1.5.0:-:*:*:*:*:*:*
  • OR cpe:/a:linuxfoundation:containerd:1.4.12:*:*:*:*:*:*:*
  • OR cpe:/a:linuxfoundation:containerd:1.5.9:*:*:*:*:*:*:*
  • OR cpe:/a:linuxfoundation:containerd:1.6.0:-:*:*:*:*:*:*
  • AND
  • cpe:/a:ibm:robotic_process_automation_for_cloud_pak:21.0.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:robotic_process_automation_for_cloud_pak:21.0.2:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:robotic_process_automation_for_cloud_pak:21.0.3:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:94872
    P
    containerd-1.4.12-150000.65.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:3242
    P
    containerd-1.4.12-150000.65.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:406
    P
    Security update for trivy (Moderate)
    2022-06-21
    oval:org.opensuse.security:def:42184
    P
    Security update for containerd, docker (Important)
    2022-05-16
    oval:org.opensuse.security:def:482
    P
    Security update for containerd, docker (Important)
    2022-05-16
    oval:org.opensuse.security:def:94237
    P
    (Important)
    2022-05-16
    oval:org.opensuse.security:def:42385
    P
    Security update for containerd, docker (Important)
    2022-05-16
    oval:org.opensuse.security:def:1514
    P
    Security update for containerd, docker (Important)
    2022-05-16
    oval:org.opensuse.security:def:93296
    P
    (Important)
    2022-05-16
    oval:org.opensuse.security:def:93608
    P
    (Important)
    2022-05-16
    oval:org.opensuse.security:def:95298
    P
    Security update for containerd, docker (Important)
    2022-05-16
    oval:org.opensuse.security:def:94025
    P
    (Important)
    2022-05-16
    oval:org.opensuse.security:def:42286
    P
    Security update for containerd, docker (Important)
    2022-05-16
    oval:org.opensuse.security:def:992
    P
    Security update for containerd, docker (Important)
    2022-05-16
    oval:org.opensuse.security:def:94446
    P
    (Important)
    2022-05-16
    oval:org.opensuse.security:def:93136
    P
    (Important)
    2022-05-16
    oval:org.opensuse.security:def:3668
    P
    Security update for containerd, docker (Important)
    2022-05-16
    oval:org.opensuse.security:def:93454
    P
    (Important)
    2022-05-16
    oval:org.opensuse.security:def:93811
    P
    (Important)
    2022-05-16
    oval:org.opensuse.security:def:102092
    P
    Security update for containerd, docker (Important) (in QA)
    2022-04-29
    oval:org.opensuse.security:def:101685
    P
    Security update for containerd, docker (Important) (in QA)
    2022-04-29
    oval:org.opensuse.security:def:42431
    P
    Security update for containerd (Moderate)
    2022-04-19
    oval:org.opensuse.security:def:93165
    P
    (Moderate)
    2022-03-04
    oval:org.opensuse.security:def:101690
    P
    Security update for containerd (Moderate)
    2022-03-04
    oval:org.opensuse.security:def:99217
    P
    (Moderate)
    2022-03-04
    oval:org.opensuse.security:def:93483
    P
    (Moderate)
    2022-03-04
    oval:org.opensuse.security:def:100424
    P
    (Moderate)
    2022-03-04
    oval:org.opensuse.security:def:93845
    P
    (Moderate)
    2022-03-04
    oval:org.opensuse.security:def:42206
    P
    Security update for containerd (Moderate)
    2022-03-04
    oval:org.opensuse.security:def:99491
    P
    (Moderate)
    2022-03-04
    oval:org.opensuse.security:def:94271
    P
    (Moderate)
    2022-03-04
    oval:org.opensuse.security:def:100758
    P
    (Moderate)
    2022-03-04
    oval:org.opensuse.security:def:93323
    P
    (Moderate)
    2022-03-04
    oval:org.opensuse.security:def:99753
    P
    (Moderate)
    2022-03-04
    oval:org.opensuse.security:def:93634
    P
    (Moderate)
    2022-03-04
    oval:org.opensuse.security:def:94057
    P
    (Moderate)
    2022-03-04
    oval:org.opensuse.security:def:42349
    P
    Security update for containerd (Moderate)
    2022-03-04
    oval:org.opensuse.security:def:999
    P
    Security update for containerd (Moderate)
    2022-03-04
    oval:org.opensuse.security:def:100086
    P
    (Moderate)
    2022-03-04
    oval:org.opensuse.security:def:94478
    P
    (Moderate)
    2022-03-04
    BACK
    linuxfoundation containerd *
    linuxfoundation containerd *
    linuxfoundation containerd *
    debian debian linux 11.0
    fedoraproject fedora 34
    fedoraproject fedora 35
    fedoraproject fedora 36
    linuxfoundation containerd 1.5.0 -
    linuxfoundation containerd 1.4.12
    linuxfoundation containerd 1.5.9
    linuxfoundation containerd 1.6.0 -
    ibm robotic process automation for cloud pak 21.0.1
    ibm robotic process automation for cloud pak 21.0.2
    ibm robotic process automation for cloud pak 21.0.3