Improper Privilege Management in containerd - CVE-2023-25173

 

Improper Privilege Management in containerd - CVE-2023-25173

Published: February 16, 2023


Vulnerability identifier: #VU72320
CSH Severity: Low
CVSS v4 BT: 5.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2023-25173
CWE-ID: CWE-269
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges.

The vulnerability exists due to improper privilege management where supplementary groups are not set up properly inside a container. A local user can use supplementary group access to bypass primary group restrictions and compromise the container.


Affected software

containerd
Dell EMC PowerProtect Data Protection
Dell Data Protection Central
ObjectScale
DB2 Data Management Console
DB2 Data Management Console on CPD
Dell EMC Streaming Data Platform
IBM Watson Machine Learning Accelerator
IBM Cloud Pak for Watson AIOps
DB2 on Cloud Pak for Data
IBM Sterling Order Management
Robotic Process Automation for Cloud Pak
Oracle Linux
Gentoo Linux
Amazon Linux AMI
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
SUSE Enterprise Storage
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Anolis OS
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Package Hub 15
Containers Module
Ubuntu
openEuler
Fedora
IBM Cloud Pak for Security
IBM Cloud Transformation Advisor
IBM Watson Assistant for IBM Cloud Pak for Data
IBM MQ Operator
IBM Match 360
IBM Cloud Pak for Data Scheduling
IBM Decision Optimization for Cloud Pak for Data
Data Replication on Cloud Pak for Data
Red Hat OpenShift Serverless
OpenShift Container Platform for Windows Containers
OpenShift Virtualization
Windows Container Support for Red Hat OpenShift
OpenShift API for Data Protection (OADP)
OpenShift Security Profiles Operator
Migration Toolkit for Containers
OpenShift Serverless Client
IBM Edge Application Manager
Red Hat OpenShift Container Platform
QRadar Suite
containerd (Ubuntu package)
toolbox
toolbox-tests
udica
stargz-snapshotter
runc
containerd
slirp4netns
oci-seccomp-bpf-hook
containernetworking-plugins
app-containers/containerd
aardvark-dns
netavark
openshift-serverless-clients (Red Hat package)
crun
fuse-overlayfs
skopeo
skopeo-tests
buildah
buildah-tests
buildah (Red Hat package)
containers-common
conmon
container-selinux
helm-zsh-completion
helm
helm-fish-completion
helm-bash-completion
helm-debuginfo
crit
criu
criu-devel
criu-libs
python3-criu
libslirp
libslirp-devel
python3-podman
podman (Red Hat package)
podman-docker
podman-tests
podman-remote
podman-plugins
podman-gvproxy
podman-catatonit
podman
moby-engine
cockpit-podman
Cloud Pak for Data
IBM InfoSphere Information Server

How to mitigate CVE-2023-25173

Install updates from vendor's website.

containerd - addressed in versions 1.5.18, 1.6.18
ObjectScale - update to 1.3.0
Red Hat OpenShift Serverless - update to 1.29.0
OpenShift API for Data Protection (OADP) - update to 1.1.6
Migration Toolkit for Containers - update to 1.7.9
QRadar Suite - update to 1.10.19.0
OpenShift Serverless Client - update to 1.29.0
IBM Cloud Transformation Advisor - update to 3.10.2
DB2 Data Management Console - update to 3.1.13.1
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.7.0
DB2 Data Management Console on CPD - update to 4.7.2
Red Hat OpenShift Container Platform - addressed in versions 4.12.30, 4.13.0, 4.13.3, 4.13.6
OpenShift Container Platform for Windows Containers - addressed in versions 6.0.1, 8.0.0
containerd (Ubuntu package) - addressed in versions Ubuntu Pro, 1.6.12-0ubuntu1~20.04.3, 1.6.12-0ubuntu1~22.04.3, 1.6.12-0ubuntu1~22.10.2, 1.6.12-0ubuntu3.1
toolbox - update to 0.0.99.4-5.0.1
toolbox-tests - update to 0.0.99.4-5.0.1
udica - update to 0.2.6-20
stargz-snapshotter - addressed in versions 0.14.2-1.fc37, 0.14.2-1.fc38
runc - update to 1.1.12-1.0.1
containerd - update to 1.2.0-209
slirp4netns - update to 1.2.1-1
oci-seccomp-bpf-hook - update to 1.2.9-1
containernetworking-plugins - update to 1.3.0-8.0.1
app-containers/containerd - update to 1.6.19
containerd - addressed in versions 1.6.19-1, 1.7.2-1
containerd - addressed in versions 1.6.19-1.fc36, 1.6.19-1.fc37, 1.6.19-1.fc38, 1.6.23-1.fc37, 1.6.23-1.fc38
Dell EMC Streaming Data Platform - update to 1.7.0
OpenShift Security Profiles Operator - update to 1.7.0
aardvark-dns - update to 1.7.0-2.0.1
netavark - update to 1.7.0-2.0.1
openshift-serverless-clients (Red Hat package) - update to 1.8.1-3.el8
crun - update to 1.8.7-1
fuse-overlayfs - update to 1.12-1.0.1
skopeo - update to 1.13.3-3.0.1
skopeo-tests - update to 1.13.3-3.0.1
buildah - update to 1.31.3-1
buildah-tests - update to 1.31.3-1
buildah (Red Hat package) - update to 1.31.3-1.el9
containers-common - update to 1-71.0.1
IBM MQ Operator - addressed in versions 2.0.17, 3.0.0
conmon - update to 2.1.8-1
container-selinux - update to 2.221.0-1
helm-zsh-completion - update to 3.13.1-150000.1.26.1
helm - update to 3.13.1-150000.1.26.1
helm-fish-completion - update to 3.13.1-150000.1.26.1
helm-bash-completion - update to 3.13.1-150000.1.26.1
helm-debuginfo - update to 3.13.1-150000.1.26.1
crit - update to 3.18-5
criu - update to 3.18-5
criu-devel - update to 3.18-5
criu-libs - update to 3.18-5
python3-criu - update to 3.18-5
IBM Watson Machine Learning Accelerator - update to 4.0
IBM Cloud Pak for Watson AIOps - update to 4.1.1
libslirp - update to 4.4.0-1
libslirp-devel - update to 4.4.0-1
python3-podman - update to 4.6.0-1
podman (Red Hat package) - update to 4.6.1-5.el9
podman-docker - update to 4.6.1-8.0.1
podman-tests - update to 4.6.1-8.0.1
podman-remote - update to 4.6.1-8.0.1
podman-plugins - update to 4.6.1-8.0.1
podman-gvproxy - update to 4.6.1-8.0.1
podman-catatonit - update to 4.6.1-8.0.1
podman - update to 4.6.1-8.0.1
IBM Match 360 - update to 4.7.0
IBM Cloud Pak for Data Scheduling - update to 4.8.0
IBM Decision Optimization for Cloud Pak for Data - update to 4.8
Data Replication on Cloud Pak for Data - update to 4.8.0
DB2 on Cloud Pak for Data - update to 4.8.4
Cloud Pak for Data - update to 4.8.5
OpenShift Virtualization - update to 4.14.0
Windows Container Support for Red Hat OpenShift - update to 7.1.0
IBM Sterling Order Management - update to 10.0.2403.1
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 1
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.6, 23.0.6
moby-engine - addressed in versions 24.0.5-1.fc37, 24.0.5-1.fc38, 24.0.5-1.fc39
cockpit-podman - update to 75-1

External References

Related Security Bulletins