← Back to CVE List

CVE-2022-27652

Published: 2022-04-18T17:15Z
Last Modified: 2024-11-21T06:56Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
A flaw was found in cri-o, where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt