A flaw was found in crun where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers were started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs.
[
{
"target": {
"function": "crun_command_exec",
"file": "src/exec.c"
},
"source": "https://github.com/containers/crun/commit/1aeeed2e4fdeffb4875c0d0b439915894594c8c6",
"deprecated": false,
"id": "CVE-2022-27650-1369fec2",
"signature_type": "Function",
"signature_version": "v1",
"digest": {
"function_hash": "326576470114948350835089168532588116583",
"length": 2525.0
}
},
{
"target": {
"file": "src/exec.c"
},
"source": "https://github.com/containers/crun/commit/1aeeed2e4fdeffb4875c0d0b439915894594c8c6",
"deprecated": false,
"id": "CVE-2022-27650-4606fc3a",
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"191965596629947503200297707270879748438",
"277783579743923417092443488377794187094",
"59215860372849921584264298802818030309",
"24826462537997860227952450397939357386",
"223256907618760933842021811521439593391"
]
}
}
]