Incorrect default permissions in buildah - CVE-2022-27651

 

Incorrect default permissions in buildah - CVE-2022-27651

Published: April 1, 2022


Vulnerability identifier: #VU61797
CSH Severity: Medium
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-27651
CWE-ID: CWE-276
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to escalate privileges on the system.

The vulnerability exists due to incorrect default permissions for files and folders that are set by the application. A remote attacker can view contents of files and directories or modify them.


Affected software

buildah
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Enterprise Storage
Red Hat Enterprise Linux for Power, little endian
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Module for Containers
openSUSE Leap
Fedora
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
toolbox
toolbox-tests
containers-common
skopeo
skopeo-tests
udica
slirp4netns
fuse-overlayfs
containernetworking-plugins
crun
runc
aardvark-dns
netavark
python-podman-api
oci-seccomp-bpf-hook
podman-docker
podman-remote
podman
podman-tests
buildah-tests
buildah
conmon
container-selinux
podman-plugins
podman-catatonit
python3-criu
criu
crit
criu-libs
criu-devel
python3-podman
podman-gvproxy
libslirp
libslirp-devel
cockpit-podman

How to mitigate CVE-2022-27651

Install updates from vendor's website.

buildah - addressed in versions 1.24.3, 1.25.0, 1.23.4
toolbox - addressed in versions 0.0.7-1, 0.0.99.3-0.4, 0.0.99.3-1
toolbox-tests - addressed in versions 0.0.99.3-0.4, 0.0.99.3-1
containers-common - addressed in versions 0.1.41-4, 1.2.4-1, 1-27
skopeo - addressed in versions 0.1.41-4, 1.2.4-1, 1.6.1-2
skopeo-tests - addressed in versions 0.1.41-4, 1.2.4-1, 1.6.1-2
udica - addressed in versions 0.2.1-2, 0.2.4-1, 0.2.6-2
slirp4netns - addressed in versions 0.4.2-3.git21fdece, 1.1.8-1, 1.1.8-2
fuse-overlayfs - addressed in versions 0.7.8-1, 1.4.0-2, 1.8.2-1
containernetworking-plugins - addressed in versions 0.8.3-4, 0.9.1-1, 1.0.1-2
crun - addressed in versions 0.18-2, 1.4.4-1
runc - addressed in versions 1.0.0-66.rc10, 1.0.0-73.rc95, 1.0.3-2
aardvark-dns - update to 1.0.1-27
netavark - update to 1.0.1-27
python-podman-api - update to 1.2.0-0.2.gitd0a45fe
oci-seccomp-bpf-hook - addressed in versions 1.2.0-3, 1.2.3-3
podman-docker - addressed in versions 1.6.4-28, 3.0.1-8, 4.0.2-6
podman-remote - addressed in versions 1.6.4-28, 3.0.1-8, 4.0.2-6
podman - addressed in versions 1.6.4-28, 3.0.1-8, 4.0.2-6
podman-tests - addressed in versions 1.6.4-28, 3.0.1-8, 4.0.2-6
buildah-tests - addressed in versions 1.11.6-10, 1.19.9-2, 1.24.2-4
buildah - addressed in versions 1.11.6-10, 1.19.9-2, 1.24.2-4
buildah - addressed in versions 1.23.3-1.fc34, 1.23.3-2.fc35, 1.25.1-1.fc36
buildah - addressed in versions 1.25.1-150100.3.13.12, 1.25.1-150300.8.6.1, 1.25.1-150400.3.3.28
conmon - addressed in versions 2.0.15-1, 2.0.26-1, 2.1.0-1
container-selinux - addressed in versions 2.130.0-1, 2.167.0-1, 2.179.1-1
podman-plugins - addressed in versions 3.0.1-8, 4.0.2-6
podman-catatonit - addressed in versions 3.0.1-8, 4.0.2-6
python3-criu - addressed in versions 3.12-9, 3.15-1, 3.15-3
criu - addressed in versions 3.12-9, 3.15-1, 3.15-3
crit - addressed in versions 3.12-9, 3.15-1, 3.15-3
criu-libs - update to 3.15-3
criu-devel - update to 3.15-3
python3-podman - update to 4.0.0-1
podman-gvproxy - update to 4.0.2-6
libslirp - addressed in versions 4.3.1-1, 4.4.0-1
libslirp-devel - addressed in versions 4.3.1-1, 4.4.0-1
cockpit-podman - addressed in versions 11-1, 29-2, 43-1

External References

Related Security Bulletins