Permissions, Privileges, and Access Controls in containerd - CVE-2022-24769
Published: March 24, 2022
Vulnerability identifier: #VU61600
CSH Severity: Medium
CVSS v4 BT: 2.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2022-24769
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to containers are incorrectly started with non-empty inheritable Linux process capabilities, which leads to security restrictions bypass and privilege escalation.
Affected software
containerd
PowerStore X
PowerStore T
IBM Cloud Pak for Watson AIOps
Storage Ceph
Amazon Linux AMI
Gentoo Linux
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Linux Enterprise Micro
SUSE Enterprise Storage
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Containers
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server for SAP
openSUSE Leap
Ubuntu
openEuler
Fedora
containerd (Debian package)
SUSE Linux Enterprise Module for Packagehub Subpackages
containerd (Ubuntu package)
containerd
containerd-ctr
app-containers/containerd
docker-engine
docker
docker-debuginfo
docker-kubic-kubeadm-criconfig
docker-kubic
docker-kubic-debuginfo
docker-zsh-completion
docker-kubic-zsh-completion
docker-kubic-fish-completion
docker-kubic-bash-completion
docker-fish-completion
docker-bash-completion
moby-engine
IBM Edge Application Manager
Red Hat OpenShift Container Platform
moby
IBM Concert Software
IBM Cloud Transformation Advisor
Dell EMC VxRail Appliance
IBM InfoSphere Information Server
PowerStore X
PowerStore T
IBM Cloud Pak for Watson AIOps
Storage Ceph
Amazon Linux AMI
Gentoo Linux
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Linux Enterprise Micro
SUSE Enterprise Storage
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Containers
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server for SAP
openSUSE Leap
Ubuntu
openEuler
Fedora
containerd (Debian package)
SUSE Linux Enterprise Module for Packagehub Subpackages
containerd (Ubuntu package)
containerd
containerd-ctr
app-containers/containerd
docker-engine
docker
docker-debuginfo
docker-kubic-kubeadm-criconfig
docker-kubic
docker-kubic-debuginfo
docker-zsh-completion
docker-kubic-zsh-completion
docker-kubic-fish-completion
docker-kubic-bash-completion
docker-fish-completion
docker-bash-completion
moby-engine
IBM Edge Application Manager
Red Hat OpenShift Container Platform
moby
IBM Concert Software
IBM Cloud Transformation Advisor
Dell EMC VxRail Appliance
IBM InfoSphere Information Server
How to mitigate CVE-2022-24769
Install updates from vendor's website.
containerd - addressed in versions 1.5.11, 1.6.2
containerd (Debian package) - update to 1.4.13~ds1-1~deb11u2
Red Hat OpenShift Container Platform - addressed in versions 4.6.57, 4.6.58, 4.7.50, 4.8.37, 4.9.29, 4.10.10
moby - update to 20.10.14
IBM Concert Software - update to 1.0.1
containerd (Ubuntu package) - addressed in versions 1.5.9-0ubuntu1~18.04.2, 1.5.9-0ubuntu1~20.04.6, 1.5.9-0ubuntu3.1, 1.6.4-0ubuntu1.1
containerd - addressed in versions 1.5.11-16.57.1, 1.5.11-150000.68.1
containerd-ctr - update to 1.5.11-150000.68.1
containerd - addressed in versions 1.6.2-1.fc35, 1.6.2-1.fc36, 1.6.2-2.fc34
containerd - update to 1.6.8-2
app-containers/containerd - update to 1.6.14
PowerStore X - update to 3.2.1.0-1989710
PowerStore T - update to 3.2.1.0-1989710
IBM Cloud Transformation Advisor - update to 3.10.1
IBM Cloud Pak for Watson AIOps - update to 4.7.0
Dell EMC VxRail Appliance - addressed in versions 7.0.372, 8.0.000
Storage Ceph - update to 7.1
IBM InfoSphere Information Server - update to 11.7.1 Fix Pack 4
docker-engine - update to 18.09.0-233
docker - addressed in versions 20.10.14_ce-98.80.1, 20.10.14_ce-150000.163.1
docker-debuginfo - addressed in versions 20.10.14_ce-98.80.1, 20.10.14_ce-150000.163.1
docker-kubic-kubeadm-criconfig - update to 20.10.14_ce-150000.163.1
docker-kubic - update to 20.10.14_ce-150000.163.1
docker-kubic-debuginfo - update to 20.10.14_ce-150000.163.1
docker-zsh-completion - update to 20.10.14_ce-150000.163.1
docker-kubic-zsh-completion - update to 20.10.14_ce-150000.163.1
docker-kubic-fish-completion - update to 20.10.14_ce-150000.163.1
docker-kubic-bash-completion - update to 20.10.14_ce-150000.163.1
docker-fish-completion - update to 20.10.14_ce-150000.163.1
docker-bash-completion - update to 20.10.14_ce-150000.163.1
moby-engine - addressed in versions 20.10.14-1.fc34, 20.10.14-1.fc35, 20.10.14-1.fc36
containerd (Debian package) - update to 1.4.13~ds1-1~deb11u2
Red Hat OpenShift Container Platform - addressed in versions 4.6.57, 4.6.58, 4.7.50, 4.8.37, 4.9.29, 4.10.10
moby - update to 20.10.14
IBM Concert Software - update to 1.0.1
containerd (Ubuntu package) - addressed in versions 1.5.9-0ubuntu1~18.04.2, 1.5.9-0ubuntu1~20.04.6, 1.5.9-0ubuntu3.1, 1.6.4-0ubuntu1.1
containerd - addressed in versions 1.5.11-16.57.1, 1.5.11-150000.68.1
containerd-ctr - update to 1.5.11-150000.68.1
containerd - addressed in versions 1.6.2-1.fc35, 1.6.2-1.fc36, 1.6.2-2.fc34
containerd - update to 1.6.8-2
app-containers/containerd - update to 1.6.14
PowerStore X - update to 3.2.1.0-1989710
PowerStore T - update to 3.2.1.0-1989710
IBM Cloud Transformation Advisor - update to 3.10.1
IBM Cloud Pak for Watson AIOps - update to 4.7.0
Dell EMC VxRail Appliance - addressed in versions 7.0.372, 8.0.000
Storage Ceph - update to 7.1
IBM InfoSphere Information Server - update to 11.7.1 Fix Pack 4
docker-engine - update to 18.09.0-233
docker - addressed in versions 20.10.14_ce-98.80.1, 20.10.14_ce-150000.163.1
docker-debuginfo - addressed in versions 20.10.14_ce-98.80.1, 20.10.14_ce-150000.163.1
docker-kubic-kubeadm-criconfig - update to 20.10.14_ce-150000.163.1
docker-kubic - update to 20.10.14_ce-150000.163.1
docker-kubic-debuginfo - update to 20.10.14_ce-150000.163.1
docker-zsh-completion - update to 20.10.14_ce-150000.163.1
docker-kubic-zsh-completion - update to 20.10.14_ce-150000.163.1
docker-kubic-fish-completion - update to 20.10.14_ce-150000.163.1
docker-kubic-bash-completion - update to 20.10.14_ce-150000.163.1
docker-fish-completion - update to 20.10.14_ce-150000.163.1
docker-bash-completion - update to 20.10.14_ce-150000.163.1
moby-engine - addressed in versions 20.10.14-1.fc34, 20.10.14-1.fc35, 20.10.14-1.fc36
External References
Related Security Bulletins
- Privilege escalation in Containerd
- Privilege escalation in Moby
- Multiple vulnerabilities in OpenShift Container Platform 4.9
- Multiple vulnerabilities in OpenShift Container Platform 4.10
- Multiple vulnerabilities in OpenShift Container Platform 4.8
- Amazon Linux AMI update for containerd, docker
- Multiple vulnerabilities in OpenShift Container Platform 4.6
- Multiple vulnerabilities in OpenShift Container Platform 4.7
- Multiple vulnerabilities in OpenShift Container Platform 4.6
- Debian update for containerd
- Multiple vulnerabilities in Dell VxRail
- Ubuntu update for containerd
- Multiple vulnerabilities in Dell VxRail Appliance components
- SUSE update for containerd, docker
- SUSE update for containerd, docker
- Multiple vulnerabilities in IBM Edge Application Manager
- Multiple vulnerabilities in IBM Edge Application Manager
- Multiple vulnerabilities in Dell PowerStore Family
- Gentoo update for containerd
- openEuler update for docker
- Amazon Linux AMI update for containerd
- Multiple vulnerabilities in IBM Storage Ceph
- Multiple vulnerabilities in IBM Concert
- Fedora 35 update for containerd
- Fedora 36 update for containerd
- Fedora 34 update for containerd
- Fedora 35 update for moby-engine
- Fedora 34 update for moby-engine
- Fedora 36 update for moby-engine
- Multiple vulnerabilities in IBM InfoSphere Information Server
- Multiple vulnerabilities in IBM Cloud Pak for AIOps
- Multiple vulnerabilities in IBM Cloud Transformation Advisor