PT-2022-7292 · Cri-O+2 · Cri-O+2

Steven J. Murdoch

·

Published

2022-09-19

·

Updated

2025-05-29

·

CVE-2022-2995

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions CRI-O (affected versions not specified)
Description The issue is related to the incorrect handling of supplementary groups in the CRI-O container engine, which may lead to sensitive information disclosure or possible data modification. This can occur if an attacker has direct access to the affected container, where supplementary groups are used to set access permissions, and is able to execute binary code in that container. The vulnerability is associated with improper control of access and may allow an attacker to disclose confidential information or modify arbitrary data. In some cases, it may also enable privilege escalation within the container. The problem arises when SGID programs are executed in a container, potentially allowing access to files with negative group permissions for the user's primary group.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Incorrect Permission

Improper Access Control

Weakness Enumeration

Related Identifiers

ALT-PU-2023-1519
ALT-PU-2023-1528
AZL-39882
BDU:2024-02407
CVE-2022-2995
GHSA-PHJR-8J92-W5V7
GO-2022-1008
GO-2022-1014
GO-2023-1574
OESA-2024-1251
RHSA-2022:7398
RHSA-2023:3216
RHSA-2023:3541

Affected Products

Alt Linux
Cri-O
Red Os