Permissions, Privileges, and Access Controls in containerd - CVE-2022-24769

 

Permissions, Privileges, and Access Controls in containerd - CVE-2022-24769

Published: March 24, 2022


Vulnerability identifier: #VU61600
CSH Severity: Medium
CVSS v4 BT: 2.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2022-24769
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to escalate privileges on the system.

The vulnerability exists due to containers are incorrectly started with non-empty inheritable Linux process capabilities, which leads to security restrictions bypass and privilege escalation.


Affected software

containerd
PowerStore X
PowerStore T
IBM Cloud Pak for Watson AIOps
Storage Ceph
Amazon Linux AMI
Gentoo Linux
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Linux Enterprise Micro
SUSE Enterprise Storage
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Containers
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server for SAP
openSUSE Leap
Ubuntu
openEuler
Fedora
containerd (Debian package)
SUSE Linux Enterprise Module for Packagehub Subpackages
containerd (Ubuntu package)
containerd
containerd-ctr
app-containers/containerd
docker-engine
docker
docker-debuginfo
docker-kubic-kubeadm-criconfig
docker-kubic
docker-kubic-debuginfo
docker-zsh-completion
docker-kubic-zsh-completion
docker-kubic-fish-completion
docker-kubic-bash-completion
docker-fish-completion
docker-bash-completion
moby-engine
IBM Edge Application Manager
Red Hat OpenShift Container Platform
moby
IBM Concert Software
IBM Cloud Transformation Advisor
Dell EMC VxRail Appliance
IBM InfoSphere Information Server

How to mitigate CVE-2022-24769

Install updates from vendor's website.

containerd - addressed in versions 1.5.11, 1.6.2
containerd (Debian package) - update to 1.4.13~ds1-1~deb11u2
Red Hat OpenShift Container Platform - addressed in versions 4.6.57, 4.6.58, 4.7.50, 4.8.37, 4.9.29, 4.10.10
moby - update to 20.10.14
IBM Concert Software - update to 1.0.1
containerd (Ubuntu package) - addressed in versions 1.5.9-0ubuntu1~18.04.2, 1.5.9-0ubuntu1~20.04.6, 1.5.9-0ubuntu3.1, 1.6.4-0ubuntu1.1
containerd - addressed in versions 1.5.11-16.57.1, 1.5.11-150000.68.1
containerd-ctr - update to 1.5.11-150000.68.1
containerd - addressed in versions 1.6.2-1.fc35, 1.6.2-1.fc36, 1.6.2-2.fc34
containerd - update to 1.6.8-2
app-containers/containerd - update to 1.6.14
PowerStore X - update to 3.2.1.0-1989710
PowerStore T - update to 3.2.1.0-1989710
IBM Cloud Transformation Advisor - update to 3.10.1
IBM Cloud Pak for Watson AIOps - update to 4.7.0
Dell EMC VxRail Appliance - addressed in versions 7.0.372, 8.0.000
Storage Ceph - update to 7.1
IBM InfoSphere Information Server - update to 11.7.1 Fix Pack 4
docker-engine - update to 18.09.0-233
docker - addressed in versions 20.10.14_ce-98.80.1, 20.10.14_ce-150000.163.1
docker-debuginfo - addressed in versions 20.10.14_ce-98.80.1, 20.10.14_ce-150000.163.1
docker-kubic-kubeadm-criconfig - update to 20.10.14_ce-150000.163.1
docker-kubic - update to 20.10.14_ce-150000.163.1
docker-kubic-debuginfo - update to 20.10.14_ce-150000.163.1
docker-zsh-completion - update to 20.10.14_ce-150000.163.1
docker-kubic-zsh-completion - update to 20.10.14_ce-150000.163.1
docker-kubic-fish-completion - update to 20.10.14_ce-150000.163.1
docker-kubic-bash-completion - update to 20.10.14_ce-150000.163.1
docker-fish-completion - update to 20.10.14_ce-150000.163.1
docker-bash-completion - update to 20.10.14_ce-150000.163.1
moby-engine - addressed in versions 20.10.14-1.fc34, 20.10.14-1.fc35, 20.10.14-1.fc36

External References

Related Security Bulletins