• CVE-2022-27652

发布时间: 2022年7月5日

修改时间: 2022年7月5日

概要

A flaw was found in cri-o, where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs.

CVSS v3 指标

NVD openEuler
CVSS评分 5.3 5.3
Attack Vector Local Local
Attack Complexity Low Low
Privileges Required Low Low
User Interaction None None
Scope Unchanged Unchanged
Confidentiality Low Low
Integrity Low Low
Availability Low Low

安全公告

公告名 概要 发布时间
KylinSec-SA-2022-1583 A flaw was found in cri-o, where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs. 2022年7月5日

影响产品

产品 状态
KY3.4-4A docker Unaffected
KY3.4-5 docker Unaffected
KY3.5.1 docker Unaffected