FlawAtlas
Search the atlas
ALSA-2022:1565 Not scored

Moderate: container-tools:3.0 security and bug fix update

The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc. Security Fix(es): * podman: Default inheritable capabilities for linux container should be empty (CVE-2022-27649) * buildah: Default inheritable capabilities for linux container should be empty (CVE-2022-27651) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Bug Fix(es): * 3.0 stable stream: podman run --pid=host command causes OCI permission error (BZ#2070961)

Exploit probability Not scored
Published April 26, 2022
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

AlmaLinux:8 buildah
AlmaLinux:8 buildah-tests
AlmaLinux:8 cockpit-podman
AlmaLinux:8 conmon
AlmaLinux:8 container-selinux
AlmaLinux:8 containernetworking-plugins
AlmaLinux:8 containers-common
AlmaLinux:8 crit
AlmaLinux:8 criu
AlmaLinux:8 crun
AlmaLinux:8 fuse-overlayfs
AlmaLinux:8 libslirp
AlmaLinux:8 libslirp-devel
AlmaLinux:8 oci-seccomp-bpf-hook
AlmaLinux:8 podman
AlmaLinux:8 podman-catatonit
AlmaLinux:8 podman-docker
AlmaLinux:8 podman-plugins
AlmaLinux:8 podman-remote
AlmaLinux:8 podman-tests
AlmaLinux:8 python3-criu
AlmaLinux:8 runc
AlmaLinux:8 skopeo
AlmaLinux:8 skopeo-tests
AlmaLinux:8 slirp4netns
AlmaLinux:8 toolbox
AlmaLinux:8 toolbox-tests
AlmaLinux:8 udica

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities ALSA-2022:1565

The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc. Security Fix(es): * podman: Default inheritable capabilities for linux container should be empty (CVE-2022-27649) * buildah: Default inheritable capabilities for linux container should be empty (CVE-2022-27651) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Bug Fix(es): * 3.0 stable stream: podman run --pid=host command causes OCI permission error (BZ#2070961)

View original source

05 / REFERENCES

Further evidence