PT-2022-19895 · Docker+8 · Docker+9

Steven J. Murdoch

·

Published

2022-08-22

·

Updated

2025-08-28

·

CVE-2022-2989

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Moby (Docker Engine) versions prior to 20.10.18 Podman (affected versions not specified) CRI-O (affected versions not specified) Buildah (affected versions not specified) Docker (affected versions not specified)
Description An incorrect handling of supplementary groups in container engines might lead to sensitive information disclosure or possible data modification if an attacker has direct access to the affected container and is able to execute binary code. This issue can allow attackers to bypass primary group restrictions, potentially gaining access to sensitive information or gaining the ability to execute code in the container. The problem occurs when supplementary groups are not set up properly, permitting unauthorized access to files.
Recommendations For Moby (Docker Engine) versions prior to 20.10.18, update to version 20.10.18 or later. For users unable to upgrade to Moby (Docker Engine) version 20.10.18 or later, do not use the "USER $USERNAME" Dockerfile instruction; instead, call ENTRYPOINT ["su", "-", "user"] to set up supplementary groups properly. As a temporary workaround for other affected container engines, consider restricting access to containers where supplementary groups are used to set access permissions until a patch is available. For containers where SGID programs are executed, consider disabling the execution of these programs until the issue is resolved.

Exploit

Fix

Improper Privilege Management

Incorrect Permission

Improper Access Control

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ALSA-2022:7822
ALSA-2022:8008
ALSA-2022:8431
ALSA-2023:2802
ALT-PU-2025-10794
AZL-10964
AZL-36976
CESA-2022_7822
CESA-2023_2802
CVE-2022-2989
GHSA-4WJJ-JWC9-2X96
GHSA-FJM8-M7M6-2FJP
GHSA-HMFX-3PCX-653P
GHSA-PHJR-8J92-W5V7
GHSA-RC4R-WH2Q-Q6C4
GO-2022-0985
GO-2022-1008
GO-2022-1014
GO-2023-1574
MGASA-2023-0213
OESA-2025-1073
OESA-2025-1074
OPENSUSE-SU-2022_3819-1
OPENSUSE-SU-2022_3820-1
OPENSUSE-SU-2023_0187-1
OPENSUSE-SU-2024:12556-1
RHSA-2022:7822
RHSA-2022:8008
RHSA-2022:8431
RHSA-2022_7822
RHSA-2022_8008
RHSA-2022_8431
RHSA-2023:2802
RHSA-2023:3613
RHSA-2023_2802
RLSA-2022:7822
SUSE-SU-2022:3819-1
SUSE-SU-2022:3820-1
SUSE-SU-2022_3819-1
SUSE-SU-2022_3820-1
SUSE-SU-2023:0187-1
SUSE-SU-2023:0326-1
USN-6295-1

Affected Products

Alt Linux
Almalinux
Centos
Docker
Linuxmint
Moby
Red Hat
Rocky Linux
Suse
Ubuntu