MGASA-2022-0192

Source
https://advisories.mageia.org/MGASA-2022-0192.html
Import Source
https://advisories.mageia.org/MGASA-2022-0192.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2022-0192
Related
Published
2022-05-21T08:50:18Z
Modified
2022-05-21T07:58:59Z
Summary
Updated opencontainers-runc packages fix security vulnerability
Details

A bug was found in runc where runc exec --cap executed processes with non-empty inheritable Linux process capabilities, creating an atypical Linux environment and enabling programs with inheritable file capabilities to elevate those capabilities to the permitted set during execve(2). This bug did not affect the container security sandbox as the inheritable set never contained more capabilities than were included in the container's bounding set. (CVE-2022-29162)

References
Credits

Affected packages

Mageia:8 / opencontainers-runc

Package

Name
opencontainers-runc
Purl
pkg:rpm/mageia/opencontainers-runc?distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.1.2-2.mga8

Ecosystem specific

{
    "section": "core"
}