CVE-2022-24769

Moby is an open-source project created by Docker to enable and accelerate software containerization. A bug was found in Moby (Docker Engine) prior to version 20.10.14 where containers were incorrectly started with non-empty inheritable Linux process capabilities, creating an atypical Linux environment and enabling programs with inheritable file capabilities to elevate those capabilities to the permitted set during `execve(2)`. Normally, when executable programs have specified permitted file capabilities, otherwise unprivileged users and processes can execute those programs and gain the specified file capabilities up to the bounding set. Due to this bug, containers which included executable programs with inheritable file capabilities allowed otherwise unprivileged users and processes to additionally gain these inheritable file capabilities up to the container's bounding set. Containers which use Linux users and groups to perform privilege separation inside the container are most directly impacted. This bug did not affect the container security sandbox as the inheritable set never contained more capabilities than were included in the container's bounding set. This bug has been fixed in Moby (Docker Engine) 20.10.14. Running containers should be stopped, deleted, and recreated for the inheritable capabilities to be reset. This fix changes Moby (Docker Engine) behavior such that containers are started with a more typical Linux environment. As a workaround, the entry point of a container can be modified to use a utility like `capsh(1)` to drop inheritable capabilities prior to the primary process starting.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.9 MEDIUM
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 26%
Affected Products (NVD)
VendorProductVersion
mobyprojectmoby
𝑥
< 20.10.14
linuxfoundationrunc
𝑥
< 1.1.2
debiandebian_linux
11.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
containerd
bookworm
1.6.20~ds1-1
fixed
bullseye
1.4.13~ds1-1~deb11u4
fixed
bullseye (security)
1.4.13~ds1-1~deb11u2
fixed
sid
1.7.23~ds2-1
fixed
trixie
1.7.22~ds1-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
containerd
bionic
Fixed 1.5.9-0ubuntu1~18.04.2
released
focal
Fixed 1.5.9-0ubuntu1~20.04.6
released
impish
ignored
jammy
Fixed 1.5.9-0ubuntu3.1
released
kinetic
Fixed 1.6.4-0ubuntu1
released
lunar
not-affected
mantic
not-affected
noble
not-affected
trusty
ignored
xenial
needed
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
containerd
suse enterprise desktop 15 SP7
1.5.11-150000.68.1
fixed
suse enterprise sap 12
1.5.11-16.57.1
fixed
suse enterprise sap 12 SP3
1.5.11-16.57.1
fixed
suse enterprise sap 12 SP4
1.5.11-16.57.1
fixed
suse enterprise sap 12 SP5
1.5.11-16.57.1
fixed
suse enterprise sap 15
1.5.11-150000.68.1
fixed
suse enterprise sap 15 SP1
1.5.11-150000.68.1
fixed
suse enterprise sap 15 SP2
1.5.11-150000.68.1
fixed
suse enterprise sap 15 SP3
1.5.11-150000.68.1
fixed
suse enterprise sap 15 SP4
1.5.11-150000.68.1
fixed
suse enterprise sap 15 SP5
1.5.11-150000.68.1
fixed
suse enterprise sap 15 SP6
1.5.11-150000.68.1
fixed
suse enterprise sap 15 SP7
1.5.11-150000.68.1
fixed
suse enterprise server 12
1.5.11-16.57.1
fixed
suse enterprise server 12 SP3
1.5.11-16.57.1
fixed
suse enterprise server 12 SP4
1.5.11-16.57.1
fixed
suse enterprise server 12 SP5
1.5.11-16.57.1
fixed
suse enterprise server 15
1.5.11-150000.68.1
fixed
suse enterprise server 15 SP1
1.5.11-150000.68.1
fixed
suse enterprise server 15 SP2
1.5.11-150000.68.1
fixed
suse enterprise server 15 SP3
1.5.11-150000.68.1
fixed
suse enterprise server 15 SP4
1.5.11-150000.68.1
fixed
suse enterprise server 15 SP5
1.5.11-150000.68.1
fixed
suse enterprise server 15 SP6
1.5.11-150000.68.1
fixed
suse enterprise server 15 SP7
1.5.11-150000.68.1
fixed
containerd-ctr
suse enterprise sap 15
1.5.11-150000.68.1
fixed
suse enterprise sap 15 SP1
1.5.11-150000.68.1
fixed
suse enterprise sap 15 SP2
1.5.11-150000.68.1
fixed
suse enterprise sap 15 SP3
1.5.11-150000.68.1
fixed
suse enterprise sap 15 SP5
1.5.11-150000.68.1
fixed
suse enterprise sap 15 SP6
1.5.11-150000.68.1
fixed
suse enterprise sap 15 SP7
1.5.11-150000.68.1
fixed
suse enterprise server 15
1.5.11-150000.68.1
fixed
suse enterprise server 15 SP1
1.5.11-150000.68.1
fixed
suse enterprise server 15 SP2
1.5.11-150000.68.1
fixed
suse enterprise server 15 SP3
1.5.11-150000.68.1
fixed
suse enterprise server 15 SP5
1.5.11-150000.68.1
fixed
suse enterprise server 15 SP6
1.5.11-150000.68.1
fixed
suse enterprise server 15 SP7
1.5.11-150000.68.1
fixed
containerd-devel
suse enterprise sap 15 SP5
1.6.19-150000.87.1
fixed
suse enterprise sap 15 SP6
1.7.10-150000.108.1
fixed
suse enterprise sap 15 SP7
1.7.27-150000.123.1
fixed
suse enterprise server 15 SP5
1.6.19-150000.87.1
fixed
suse enterprise server 15 SP6
1.7.10-150000.108.1
fixed
suse enterprise server 15 SP7
1.7.27-150000.123.1
fixed
References