Non-empty default inheritable capabilities for linux container in Buildah
A bug was found in Buildah where containers were created with non-empty inheritable Linux process capabilities, creating an atypical Linux environment and enabling programs with inheritable file capabilities to elevate those capabilities to the permitted set during execve(2). This bug did not affect the container security sandbox as the inheritable set never contained more capabilities than were included in the container's bounding set.
02 / AFFECTED SOFTWARE
Affected packages
28 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
A bug was found in Buildah where containers were created with non-empty inheritable Linux process capabilities, creating an atypical Linux environment and enabling programs with inheritable file capabilities to elevate those capabilities to the permitted set during execve(2). This bug did not affect the container security sandbox as the inheritable set never contained more capabilities than were included in the container's bounding set.
Containers are created with non-empty inheritable Linux process capabilities, permitting programs with inheritable file capabilities to elevate those capabilities to the permitted set during execve(2). This bug does not affect the container security sandbox, as the inheritable set never contains more capabilities than are included in the container's bounding set.
A flaw was found in buildah where containers were incorrectly started with non-empty default permissions. A bug was found in Moby (Docker Engine) where containers were incorrectly started with non-empty inheritable Linux process capabilities, enabling an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs. This has the potential to impact confidentiality and integrity.
05 / REFERENCES
Further evidence
- https://bugzilla.redhat.com/show_bug.cgi?id=2066840
- https://github.com/containers/buildah
- https://github.com/containers/buildah/commit/90b3254c7404039c1c786999ac189654228f6e0e
- https://github.com/containers/buildah/commit/e7e55c988c05dd74005184ceb64f097a0cfe645b
- https://github.com/containers/buildah/pull/3855
- https://github.com/containers/buildah/security/advisories/GHSA-c3g4-w6cv-6v7h
- https://lists.fedoraproject.org/archives/list/[email protected]/message/25YI27MENCEPZTTGRVU6BQD5V53FNI52
- https://lists.fedoraproject.org/archives/list/[email protected]/message/2VWH6X6HOFPO6HTESF42HIJZEPXSWVIO
- https://lists.fedoraproject.org/archives/list/[email protected]/message/7NETC7I6RTMMBRJJQVJOJUPDK4W4PQSJ
- https://nvd.nist.gov/vuln/detail/CVE-2022-27651
- https://pkg.go.dev/vuln/GO-2022-0417
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/27xxx/CVE-2022-27651.json
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/25YI27MENCEPZTTGRVU6BQD5V53FNI52/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2VWH6X6HOFPO6HTESF42HIJZEPXSWVIO/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7NETC7I6RTMMBRJJQVJOJUPDK4W4PQSJ/