oss-sec mailing list archives

CVE-2022-29162: runc < 1.1.2 incorrect handling of inheritable capabilities in default configuration


From: Aleksa Sarai <asarai () suse de>
Date: Thu, 12 May 2022 15:28:23 +1000

A security update for runc (v1.1.2) was released to mitigate
CVE-2022-29162, which is a low severity vulnerability related to
mishandling of inheritable capabilities which resulted in an atypical
Linux environment inside containers.

As the inheritable set was a subset of the permitted capabilities (which
are limited) this bug does not affect the container security boundary,
it simply ensures that programs running inside the container do not
inherit capabilities they do not need accidentally. This issue is
similar to CVE-2022-24769 which was found in Docker and containerd.

As this issue was deemed not exploitable, there is no embargo for this
patch and release. Please update as soon as practical.

You can find the new version of runc on our releases page[1] and the
patch fixing the issue is [2].

[1]: https://github.com/opencontainers/runc/releases/tag/v1.1.2
[2]: https://github.com/opencontainers/runc/commit/98fe566c527479195ce3c8167136d2a555fe6b65

-- 
Aleksa Sarai
Senior Software Engineer (Containers)
SUSE Linux GmbH
<https://www.cyphar.com/>

Attachment: signature.asc
Description:


Current thread: