Improper Preservation of Permissions in moby - CVE-2021-41089

 

Improper Preservation of Permissions in moby - CVE-2021-41089

Published: June 15, 2022 / Updated: October 19, 2022


Vulnerability identifier: #VU64415
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L]
CVE-ID: CVE-2021-41089
CWE-ID: CWE-281
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to application does not properly impose security restrictions, which leads to security restrictions bypass and privilege escalation.


Affected software

moby
Gentoo Linux
Amazon Linux AMI
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Server
SUSE MicroOS
SUSE Linux Enterprise Micro
SUSE Enterprise Storage
SUSE Linux Enterprise Module for Containers
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
Ubuntu
openEuler
Fedora
IBM Edge Application Manager
Dell Secure Connect Gateway
runc
runc-debuginfo
containerd
docker-engine
docker.io (Ubuntu package)
docker
moby-engine
docker-debuginfo
docker-bash-completion
docker-fish-completion
app-containers/docker
SCALANCE LPE9403
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity XT Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)
Storage Ceph
IBM InfoSphere Information Server

How to mitigate CVE-2021-41089

Install updates from vendor's website.

moby - update to 20.10.9
Dell Secure Connect Gateway - update to 5.12.00.10
runc - addressed in versions 1.0.2-16.14.1, 1.0.2-23.1
runc-debuginfo - addressed in versions 1.0.2-16.14.1, 1.0.2-23.1
containerd - addressed in versions 1.4.11-16.45.1, 1.4.11-56.1, 1.4.12-16.49.1, 1.4.12-60.1
containerd - addressed in versions 1.5.7-1.fc34, 1.5.7-1.fc35
SCALANCE LPE9403 - update to 2.0
Dell EMC Unity VSA Operating Environment (OE) - update to 5.2.0.0.5.173
Dell EMC Unity XT Operating Environment (OE) - update to 5.2.0.0.5.173
Dell EMC Unity Operating Environment (OE) - update to 5.2.0.0.5.173
Storage Ceph - update to 7.1
IBM InfoSphere Information Server - update to 11.7.1 Fix Pack 4
docker-engine - update to 18.09.0-238
docker.io (Ubuntu package) - addressed in versions 20.10.7-0ubuntu1~18.04.2, 20.10.7-0ubuntu1~20.04.2, 20.10.7-0ubuntu1~21.04.2
docker - update to 20.10.7-3.71
moby-engine - addressed in versions 20.10.9-1.fc34, 20.10.9-1.fc35
docker-debuginfo - addressed in versions 20.10.12_ce-98.75.1, 20.10.12_ce-159.1
docker - addressed in versions 20.10.12_ce-98.75.1, 20.10.12_ce-159.1
docker-bash-completion - update to 20.10.12_ce-159.1
docker-fish-completion - update to 20.10.12_ce-159.1
app-containers/docker - update to 25.0.4

External References

Related Security Bulletins