Security restrictions bypass in Podman - CVE-2022-1227

 

Security restrictions bypass in Podman - CVE-2022-1227

Published: April 21, 2022 / Updated: April 1, 2023


Vulnerability identifier: #VU62468
CSH Severity: Medium
CVSS v4: 8.4 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-1227
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to escalate privileges on the system.

The vulnerability exists due to improper privilege management when running podman top on a container made from a maliciously-crafted image and using a user namespace. An attacker with full access to the container can execute arbitrary code  in the host context.


Affected software

Podman
podman (Red Hat package)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
toolbox-tests
toolbox
podman-tui
udica
containernetworking-plugins
crun
runc
netavark
aardvark-dns
slirp4netns
oci-seccomp-bpf-hook
skopeo-tests
skopeo
containers-common
fuse-overlayfs
podman
podman-remote
podman-tests
podman-docker
buildah
buildah-tests
conmon
container-selinux
podman-plugins
podman-catatonit
podman-cni-config
podman-debuginfo
podman-remote-debuginfo
crit
criu
python3-criu
criu-devel
criu-libs
python3-podman
podman-gvproxy
libslirp-devel
libslirp
cockpit-podman
Storage
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
Anolis OS
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
SUSE Linux Enterprise Storage
SUSE Enterprise Storage
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server
SUSE Linux Enterprise Module for Containers
SUSE Linux Enterprise High Performance Computing
openSUSE Leap
Fedora
Red Hat OpenShift Container Platform

How to mitigate CVE-2022-1227

Install updates from vendor's website.

Podman - update to 3.4.7
podman (Red Hat package) - addressed in versions 1.6.4-32.el7_9, 1.9.3-5.rhaos4.6.el8
Storage - update to 1.37.3
Red Hat OpenShift Container Platform - update to 4.6.58
toolbox-tests - addressed in versions 0.0.99.3-0.4, 0.0.99.3-1
toolbox - addressed in versions 0.0.99.3-0.4, 0.0.99.3-1
podman-tui - update to 0.2.1-1.fc35
udica - addressed in versions 0.2.4-1, 0.2.6-2
containernetworking-plugins - addressed in versions 0.9.1-1, 1.0.1-2
crun - addressed in versions 0.18-3, 1.4.4-1
runc - addressed in versions 1.0.0-73.rc95, 1.0.3-2
netavark - update to 1.0.1-27
aardvark-dns - update to 1.0.1-27
slirp4netns - addressed in versions 1.1.8-1, 1.1.8-2
oci-seccomp-bpf-hook - addressed in versions 1.2.0-3, 1.2.3-3
skopeo-tests - addressed in versions 1.2.4-1, 1.6.1-2
skopeo - addressed in versions 1.2.4-1, 1.6.1-2
containers-common - addressed in versions 1.2.4-1, 1-27
fuse-overlayfs - addressed in versions 1.4.0-2, 1.8.2-1
podman - addressed in versions 1.6.4-32, 3.0.1-9, 4.0.2-6
podman-remote - addressed in versions 1.6.4-32, 3.0.1-9, 4.0.2-6
podman-tests - addressed in versions 1.6.4-32, 3.0.1-9, 4.0.2-6
podman-docker - addressed in versions 1.6.4-32, 3.0.1-9, 4.0.2-6
buildah - addressed in versions 1.19.9-3, 1.24.2-4
buildah-tests - addressed in versions 1.19.9-3, 1.24.2-4
conmon - addressed in versions 2.0.26-1, 2.1.0-1
container-selinux - addressed in versions 2.178.0-2, 2.179.1-1
podman-plugins - addressed in versions 3.0.1-9, 4.0.2-6
podman-catatonit - addressed in versions 3.0.1-9, 4.0.2-6
podman - addressed in versions 3.4.7-1.fc34, 3.4.7-1.fc35
podman-cni-config - addressed in versions 3.4.7-150300.9.9.2, 3.4.7-150400.4.3.1
podman - addressed in versions 3.4.7-150300.9.9.2, 3.4.7-150400.4.3.1
podman-debuginfo - addressed in versions 3.4.7-150300.9.9.2, 3.4.7-150400.4.3.1
podman-remote - update to 3.4.7-150400.4.3.1
podman-remote-debuginfo - update to 3.4.7-150400.4.3.1
podman-docker - update to 3.4.7-150400.4.3.1
crit - addressed in versions 3.15-1, 3.15-3
criu - addressed in versions 3.15-1, 3.15-3
python3-criu - addressed in versions 3.15-1, 3.15-3
criu-devel - update to 3.15-3
criu-libs - update to 3.15-3
python3-podman - update to 4.0.0-1
podman-gvproxy - update to 4.0.2-6
libslirp-devel - addressed in versions 4.3.1-1, 4.4.0-1
libslirp - addressed in versions 4.3.1-1, 4.4.0-1
cockpit-podman - addressed in versions 29-2, 43-1

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins