Security restrictions bypass in containerd - CVE-2022-23648

 

Security restrictions bypass in containerd - CVE-2022-23648

Published: March 3, 2022 / Updated: March 30, 2022


Vulnerability identifier: #VU60972
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-23648
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to an error when handling specially crafted image configuration in containerd where containers launched through containerd’s CRI implementation. A remote attacker can bypass any policy-based enforcement on container setup and access the read-only copies of arbitrary files and directories on the host.


Affected software

containerd
trivy
DB2 Data Management Console
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
Dell Policy Manager for Secure Connect Gateway (SCG)
PowerStore T
PowerStore X
IBM Cloud Pak for Watson AIOps
DB2 on Cloud Pak for Data
DB2 Data Management Console on CPD
IBM supplied MQ Advanced container images
Gentoo Linux
Amazon Linux AMI
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Linux Enterprise Micro
SUSE Enterprise Storage
SUSE Linux Enterprise Module for Containers
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server for SAP
openSUSE Leap
Ubuntu
openEuler
Fedora
IBM Cloud Pak for Security
IBM Cloud Transformation Advisor
Dell Secure Connect Gateway
IBM Robotic Process Automation
IBM MQ Operator
APEX Cloud Platform for Red Hat OpenShift
containerd (Debian package)
SUSE Linux Enterprise Module for Packagehub Subpackages
containerd
containerd (Ubuntu package)
containerd-ctr
app-containers/containerd
docker
docker-debuginfo
docker-kubic-zsh-completion
docker-kubic
docker-kubic-debuginfo
docker-kubic-kubeadm-criconfig
docker-bash-completion
docker-fish-completion
docker-kubic-bash-completion
docker-kubic-fish-completion
docker-zsh-completion
QRadar Suite
IBM Edge Application Manager
Cloud Pak for Data
Dell EMC VxRail Appliance

How to mitigate CVE-2022-23648

Install updates from vendor's website.

containerd - addressed in versions 1.4.13, 1.5.10, 1.6.1
trivy - update to 0.26.0
containerd (Debian package) - update to 1.4.13~ds1-1~deb11u1
QRadar Suite - update to 1.10.19.0
IBM Cloud Transformation Advisor - update to 3.10.2
DB2 Data Management Console - update to 3.1.13.1
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.3
Dell Secure Connect Gateway - update to 5.12.00.10
Dell Policy Manager for Secure Connect Gateway (SCG) - update to 5.12.00.00
IBM Robotic Process Automation - update to 21.0.3.1
containerd - update to 1.2.0-202
containerd - addressed in versions 1.4.12-63.1, 1.4.13-16.54.1, 1.5.11-16.57.1, 1.5.11-150000.68.1
containerd (Ubuntu package) - addressed in versions 1.5.5-0ubuntu3.1, 1.5.5-0ubuntu3~18.04.2, 1.5.5-0ubuntu3~20.04.2, 1.5.9-0ubuntu1~20.04.4, 1.5.9-0ubuntu1~21.10.3
containerd-ctr - update to 1.5.11-150000.68.1
containerd - addressed in versions 1.6.1-1.fc34, 1.6.1-1.fc35, 1.6.1-1.fc36
containerd - update to 1.6.8-2
app-containers/containerd - update to 1.6.14
IBM MQ Operator - addressed in versions 2.0.4, 2.1.0
APEX Cloud Platform for Red Hat OpenShift - update to 03.01.02.00
PowerStore T - update to 3.2.1.0-1989710
PowerStore X - update to 3.2.1.0-1989710
IBM Cloud Pak for Watson AIOps - update to 4.7.0
DB2 on Cloud Pak for Data - update to 4.8.4
Cloud Pak for Data - update to 4.8.5
DB2 Data Management Console on CPD - update to 5.1.2
Dell EMC VxRail Appliance - addressed in versions 7.0.372, 8.0.000
IBM supplied MQ Advanced container images - update to 9.3.1.0
docker - addressed in versions 20.10.14_ce-98.80.1, 20.10.14_ce-150000.163.1
docker-debuginfo - addressed in versions 20.10.14_ce-98.80.1, 20.10.14_ce-150000.163.1
docker-kubic-zsh-completion - update to 20.10.14_ce-150000.163.1
docker-kubic - update to 20.10.14_ce-150000.163.1
docker-kubic-debuginfo - update to 20.10.14_ce-150000.163.1
docker-kubic-kubeadm-criconfig - update to 20.10.14_ce-150000.163.1
docker-bash-completion - update to 20.10.14_ce-150000.163.1
docker-fish-completion - update to 20.10.14_ce-150000.163.1
docker-kubic-bash-completion - update to 20.10.14_ce-150000.163.1
docker-kubic-fish-completion - update to 20.10.14_ce-150000.163.1
docker-zsh-completion - update to 20.10.14_ce-150000.163.1

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins