Skip to content

runc CVE-2022-29162

Moderate
arnaldo2792 published GHSA-v774-6wqv-56hv Jun 10, 2022

Package

runc (bottlerocket)

Affected versions

< 1.8.0

Patched versions

1.8.0

Description

A bug was found in runc where runc exec --cap executed processes with non-empty inheritable Linux process capabilities, creating an atypical Linux environment and enabling programs with inheritable file capabilities to elevate those capabilities to the permitted set during execve(2).

For more information, please refer to GHSA-f3fp-gc8g-vw66.

Severity

Moderate

CVE ID

CVE-2022-29162

Weaknesses

No CWEs