A flaw was found in crun where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers were started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs.
{ "vanir_signatures": [ { "signature_type": "Function", "deprecated": false, "digest": { "function_hash": "326576470114948350835089168532588116583", "length": 2525.0 }, "source": "https://github.com/containers/crun/commit/1aeeed2e4fdeffb4875c0d0b439915894594c8c6", "id": "CVE-2022-27650-1369fec2", "target": { "file": "src/exec.c", "function": "crun_command_exec" }, "signature_version": "v1" }, { "signature_type": "Line", "deprecated": false, "digest": { "threshold": 0.9, "line_hashes": [ "191965596629947503200297707270879748438", "277783579743923417092443488377794187094", "59215860372849921584264298802818030309", "24826462537997860227952450397939357386", "223256907618760933842021811521439593391" ] }, "source": "https://github.com/containers/crun/commit/1aeeed2e4fdeffb4875c0d0b439915894594c8c6", "id": "CVE-2022-27650-4606fc3a", "target": { "file": "src/exec.c" }, "signature_version": "v1" } ] }