Security restrictions bypass in containerd - CVE-2022-23648
Published: March 3, 2022 / Updated: March 30, 2022
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to an error when handling specially crafted image configuration in containerd where containers launched through containerd’s CRI implementation. A remote attacker can bypass any policy-based enforcement on container setup and access the read-only copies of arbitrary files and directories on the host.
Affected software
trivy
DB2 Data Management Console
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
Dell Policy Manager for Secure Connect Gateway (SCG)
PowerStore T
PowerStore X
IBM Cloud Pak for Watson AIOps
DB2 on Cloud Pak for Data
DB2 Data Management Console on CPD
IBM supplied MQ Advanced container images
Gentoo Linux
Amazon Linux AMI
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Linux Enterprise Micro
SUSE Enterprise Storage
SUSE Linux Enterprise Module for Containers
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server for SAP
openSUSE Leap
Ubuntu
openEuler
Fedora
IBM Cloud Pak for Security
IBM Cloud Transformation Advisor
Dell Secure Connect Gateway
IBM Robotic Process Automation
IBM MQ Operator
APEX Cloud Platform for Red Hat OpenShift
containerd (Debian package)
SUSE Linux Enterprise Module for Packagehub Subpackages
containerd
containerd (Ubuntu package)
containerd-ctr
app-containers/containerd
docker
docker-debuginfo
docker-kubic-zsh-completion
docker-kubic
docker-kubic-debuginfo
docker-kubic-kubeadm-criconfig
docker-bash-completion
docker-fish-completion
docker-kubic-bash-completion
docker-kubic-fish-completion
docker-zsh-completion
QRadar Suite
IBM Edge Application Manager
Cloud Pak for Data
Dell EMC VxRail Appliance
How to mitigate CVE-2022-23648
trivy - update to 0.26.0
containerd (Debian package) - update to 1.4.13~ds1-1~deb11u1
QRadar Suite - update to 1.10.19.0
IBM Cloud Transformation Advisor - update to 3.10.2
DB2 Data Management Console - update to 3.1.13.1
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.3
Dell Secure Connect Gateway - update to 5.12.00.10
Dell Policy Manager for Secure Connect Gateway (SCG) - update to 5.12.00.00
IBM Robotic Process Automation - update to 21.0.3.1
containerd - update to 1.2.0-202
containerd - addressed in versions 1.4.12-63.1, 1.4.13-16.54.1, 1.5.11-16.57.1, 1.5.11-150000.68.1
containerd (Ubuntu package) - addressed in versions 1.5.5-0ubuntu3.1, 1.5.5-0ubuntu3~18.04.2, 1.5.5-0ubuntu3~20.04.2, 1.5.9-0ubuntu1~20.04.4, 1.5.9-0ubuntu1~21.10.3
containerd-ctr - update to 1.5.11-150000.68.1
containerd - addressed in versions 1.6.1-1.fc34, 1.6.1-1.fc35, 1.6.1-1.fc36
containerd - update to 1.6.8-2
app-containers/containerd - update to 1.6.14
IBM MQ Operator - addressed in versions 2.0.4, 2.1.0
APEX Cloud Platform for Red Hat OpenShift - update to 03.01.02.00
PowerStore T - update to 3.2.1.0-1989710
PowerStore X - update to 3.2.1.0-1989710
IBM Cloud Pak for Watson AIOps - update to 4.7.0
DB2 on Cloud Pak for Data - update to 4.8.4
Cloud Pak for Data - update to 4.8.5
DB2 Data Management Console on CPD - update to 5.1.2
Dell EMC VxRail Appliance - addressed in versions 7.0.372, 8.0.000
IBM supplied MQ Advanced container images - update to 9.3.1.0
docker - addressed in versions 20.10.14_ce-98.80.1, 20.10.14_ce-150000.163.1
docker-debuginfo - addressed in versions 20.10.14_ce-98.80.1, 20.10.14_ce-150000.163.1
docker-kubic-zsh-completion - update to 20.10.14_ce-150000.163.1
docker-kubic - update to 20.10.14_ce-150000.163.1
docker-kubic-debuginfo - update to 20.10.14_ce-150000.163.1
docker-kubic-kubeadm-criconfig - update to 20.10.14_ce-150000.163.1
docker-bash-completion - update to 20.10.14_ce-150000.163.1
docker-fish-completion - update to 20.10.14_ce-150000.163.1
docker-kubic-bash-completion - update to 20.10.14_ce-150000.163.1
docker-kubic-fish-completion - update to 20.10.14_ce-150000.163.1
docker-zsh-completion - update to 20.10.14_ce-150000.163.1
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Security restrictins bypass in containerd
- Amazon Linux AMI update for containerd
- Debian update for containerd
- Security restrictions bypass in trivy
- Ubuntu update for containerd
- Ubuntu update for containerd
- Multiple vulnerabilities in DELL Secure Connect Gateway Security
- Multiple vulnerabilities in Dell Policy Manager for Secure Connect Gateway
- Multiple vulnerabilities in IBM Robotic Process Automation for Cloud Pak
- Multiple vulnerabilities in Dell VxRail
- Multiple vulnerabilities in IBM MQ Operator
- Multiple vulnerabilities in Dell VxRail Appliance components
- SUSE update for containerd
- SUSE update for containerd
- SUSE update for containerd
- SUSE update for containerd, docker
- SUSE update for containerd, docker
- Multiple vulnerabilities in IBM Edge Application Manager
- Multiple vulnerabilities in Dell PowerStore Family
- Gentoo update for containerd
- Multiple vulnerabilities in IBM QRadar Suite Software
- openEuler update for containerd
- Multiple vulnerabilities in IBM Db2 on Cloud Pak for Data
- Amazon Linux AMI update for containerd
- Multiple vulnerabilities in IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Fedora 34 update for containerd
- Fedora 35 update for containerd
- Fedora 36 update for containerd
- Multiple vulnerabilities in IBM Cloud Pak for AIOps
- Multiple vulnerabilities in Dell APEX Cloud Platform for Red Hat OpenShift
- Multiple vulnerabilities in IBM DB2 Data Management Console
- Multiple vulnerabilities in IBM watsonx Orchestrate Cartridge for IBM Cloud Pak for Data