Improper privilege management in crun - CVE-2022-27650

 

Improper privilege management in crun - CVE-2022-27650

Published: March 26, 2022 / Updated: April 27, 2026


Vulnerability identifier: #VU128070
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-27650
CWE-ID: CWE-269
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to elevate privileges.

The vulnerability exists due to improper privilege management in crun exec when creating processes inside a linux container. A local user can execute a program with inheritable file capabilities to elevate privileges.

The issue creates a non-empty inheritable capability set by default, but the inheritable set does not exceed the container's bounding set.


Affected software

crun
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Anolis OS
Fedora
toolbox-tests
toolbox
udica
containernetworking-plugins
crun
runc
aardvark-dns
netavark
slirp4netns
oci-seccomp-bpf-hook
skopeo
skopeo-tests
containers-common
fuse-overlayfs
buildah
buildah-tests
conmon
container-selinux
podman-docker
podman-tests
podman-remote
podman
podman-plugins
podman-catatonit
python3-criu
crit
criu
criu-devel
criu-libs
python3-podman
podman-gvproxy
libslirp-devel
libslirp
cockpit-podman

How to mitigate CVE-2022-27650

Install security update from vendor's website.

crun - update to 1.4.4
toolbox-tests - addressed in versions 0.0.99.3-0.4, 0.0.99.3-1
toolbox - addressed in versions 0.0.99.3-0.4, 0.0.99.3-1
udica - addressed in versions 0.2.4-1, 0.2.6-2
containernetworking-plugins - addressed in versions 0.9.1-1, 1.0.1-2
crun - addressed in versions 0.18-3, 1.4.4-1
runc - addressed in versions 1.0.0-73.rc95, 1.0.3-2
aardvark-dns - update to 1.0.1-27
netavark - update to 1.0.1-27
slirp4netns - addressed in versions 1.1.8-1, 1.1.8-2
oci-seccomp-bpf-hook - addressed in versions 1.2.0-3, 1.2.3-3
skopeo - addressed in versions 1.2.4-1, 1.6.1-2
skopeo-tests - addressed in versions 1.2.4-1, 1.6.1-2
containers-common - addressed in versions 1.2.4-1, 1-27
fuse-overlayfs - addressed in versions 1.4.0-2, 1.8.2-1
crun - update to 1.4.4-1.fc34
buildah - addressed in versions 1.19.9-3, 1.24.2-4
buildah-tests - addressed in versions 1.19.9-3, 1.24.2-4
conmon - addressed in versions 2.0.26-1, 2.1.0-1
container-selinux - addressed in versions 2.178.0-2, 2.179.1-1
podman-docker - addressed in versions 3.0.1-8, 4.0.2-6
podman-tests - addressed in versions 3.0.1-8, 4.0.2-6
podman-remote - addressed in versions 3.0.1-8, 4.0.2-6
podman - addressed in versions 3.0.1-8, 4.0.2-6
podman-plugins - addressed in versions 3.0.1-8, 4.0.2-6
podman-catatonit - addressed in versions 3.0.1-8, 4.0.2-6
python3-criu - addressed in versions 3.15-1, 3.15-3
crit - addressed in versions 3.15-1, 3.15-3
criu - addressed in versions 3.15-1, 3.15-3
criu-devel - update to 3.15-3
criu-libs - update to 3.15-3
python3-podman - update to 4.0.0-1
podman-gvproxy - update to 4.0.2-6
libslirp-devel - addressed in versions 4.3.1-1, 4.4.0-1
libslirp - addressed in versions 4.3.1-1, 4.4.0-1
cockpit-podman - addressed in versions 29-2, 43-1

External References

Related Security Bulletins