Incorrect authorization in Podman - CVE-2022-2989

 

Incorrect authorization in Podman - CVE-2022-2989

Published: November 14, 2022


Vulnerability identifier: #VU69290
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-2989
CWE-ID: CWE-863
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to incorrect handling of the supplementary groups in the Podman container engine. A local user with direct access to the affected container where supplementary groups are used can set access permissions and execute a binary code in that container.


Affected software

Podman
Gentoo Linux
Oracle Linux
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
openSUSE Leap Micro
SUSE Enterprise Storage
SUSE Linux Enterprise Storage
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Anolis OS
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Containers
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
openSUSE Leap
openEuler
Ubuntu
containerd
IBM Watson Machine Learning Accelerator
toolbox-tests
toolbox
udica
containernetworking-plugins
aardvark-dns
netavark
runc
slirp4netns
oci-seccomp-bpf-hook
crun
skopeo-tests
skopeo
fuse-overlayfs
buildah-tests
buildah
containers-common
buildah (Red Hat package)
conmon
container-selinux
podman (Ubuntu package)
podman-docker (Ubuntu package)
podman-docker
podman-remote
podman-plugins
podman-gvproxy
podman-debugsource
podman-debuginfo
podman
podman-help
podman-cni-config
podman-remote-debuginfo
crit
criu
criu-devel
criu-libs
python3-criu
python3-podman
podman-catatonit
podman-tests
podman (Red Hat package)
libslirp-devel
libslirp
app-containers/podman
cockpit-podman

How to mitigate CVE-2022-2989

Install updates from vendor's website.

Podman - update to 4.3.0
containerd - addressed in versions 1.5.18, 1.6.18
IBM Watson Machine Learning Accelerator - update to 5.0.3
toolbox-tests - update to 0.0.99.3-0.4
toolbox - update to 0.0.99.3-0.4
udica - update to 0.2.6-3
containernetworking-plugins - update to 1.0.1-2
aardvark-dns - update to 1.0.1-27
netavark - update to 1.0.1-27
runc - update to 1.0.3-2
slirp4netns - update to 1.1.8-2
oci-seccomp-bpf-hook - update to 1.2.3-3
crun - update to 1.4.4-1
skopeo-tests - update to 1.6.1-2
skopeo - update to 1.6.1-2
fuse-overlayfs - update to 1.8.2-1
buildah-tests - update to 1.24.2-4
buildah - update to 1.24.2-4
containers-common - update to 1-27
buildah (Red Hat package) - update to 1.27.0-2.el9
conmon - update to 2.1.0-1
container-selinux - update to 2.179.1-1
podman (Ubuntu package) - update to 3.4.4+ds1-1ubuntu1.22.04.2
podman-docker (Ubuntu package) - update to 3.4.4+ds1-1ubuntu1.22.04.2
podman-docker - update to 3.4.4-8
podman-remote - update to 3.4.4-8
podman-plugins - update to 3.4.4-8
podman-gvproxy - update to 3.4.4-8
podman-debugsource - update to 3.4.4-8
podman-debuginfo - update to 3.4.4-8
podman - update to 3.4.4-8
podman-help - update to 3.4.4-8
podman-debuginfo - addressed in versions 3.4.7-150300.9.12.1, 3.4.7-150400.4.6.1, 4.3.1-150300.9.15.1, 4.3.1-150400.4.11.1
podman - addressed in versions 3.4.7-150300.9.12.1, 3.4.7-150400.4.6.1, 4.3.1-150300.9.15.1, 4.3.1-150400.4.11.1
podman-cni-config - addressed in versions 3.4.7-150300.9.12.1, 3.4.7-150400.4.6.1, 4.3.1-150300.9.15.1, 4.3.1-150400.4.11.1
podman-remote - addressed in versions 3.4.7-150400.4.6.1, 4.3.1-150400.4.11.1
podman-docker - addressed in versions 3.4.7-150400.4.6.1, 4.3.1-150400.4.11.1
podman-remote-debuginfo - addressed in versions 3.4.7-150400.4.6.1, 4.3.1-150400.4.11.1
crit - update to 3.15-3
criu - update to 3.15-3
criu-devel - update to 3.15-3
criu-libs - update to 3.15-3
python3-criu - update to 3.15-3
python3-podman - update to 4.0.0-1
podman-docker - update to 4.0.2-6
podman - update to 4.0.2-6
podman-catatonit - update to 4.0.2-6
podman-gvproxy - update to 4.0.2-6
podman-plugins - update to 4.0.2-6
podman-remote - update to 4.0.2-6
podman-tests - update to 4.0.2-6
podman (Red Hat package) - update to 4.2.0-7.el9_1
libslirp-devel - update to 4.4.0-1
libslirp - update to 4.4.0-1
app-containers/podman - update to 4.9.4
cockpit-podman - update to 43-1

External References

Related Security Bulletins