FlawAtlas
Search the atlas
CVE-2022-27649 High

Podman's default inheritable capabilities for linux container not empty in github.com/containers/podman

Podman's default inheritable capabilities for linux container not empty in github.com/containers/podman

Exploit probability 1.4%
Published August 21, 2024
Required by Not available
Last source change March 3, 2026

02 / AFFECTED SOFTWARE

Affected packages

Go github.com/containers/podman/v4
Unknown Unknown

3 explicit affected versions

Go github.com/containers/podman
Go github.com/containers/podman/v2
Go github.com/containers/podman/v3
Go github.com/containers/podman/v4

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2022-27649

A flaw was found in Podman, where containers were started incorrectly with non-empty default permissions. A vulnerability was found in Moby (Docker Engine), where containers were started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs.

View original source
Open Source Vulnerabilities GHSA-qvf8-p83w-v58j

A bug was found in Podman where containers were created with non-empty inheritable Linux process capabilities, creating an atypical Linux environment and enabling programs with inheritable file capabilities to elevate those capabilities to the permitted set during execve(2). This bug did not affect the container security sandbox as the inheritable set never contained more capabilities than were included in the container's bounding set.

View original source
Open Source Vulnerabilities GO-2022-0416

Podman's default inheritable capabilities for linux container not empty in github.com/containers/podman

View original source

05 / REFERENCES

Further evidence