SB2022032618 - Improper privilege management in crun
Published: March 26, 2022 Updated: April 27, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper privilege management (CVE-ID: CVE-2022-27650)
The vulnerability allows a local user to elevate privileges.
The vulnerability exists due to improper privilege management in crun exec when creating processes inside a linux container. A local user can execute a program with inheritable file capabilities to elevate privileges.
The issue creates a non-empty inheritable capability set by default, but the inheritable set does not exceed the container's bounding set.
Remediation
Install update from vendor's website.