
Cloud Vulnerability DB
A community-led vulnerabilities database
A security regression occurred in cri-o packages released for Red Hat OpenShift Container Platform versions 4.9.48, 4.10.31, and 4.11.6, where an incorrect version of cri-o was missing the previously implemented fix for CVE-2022-27652. This regression was designated as CVE-2022-3466 and is specific to Red Hat's cri-o packages (Red Hat Bugzilla).
The vulnerability affects the handling of inheritable file capabilities in cri-o. The security regression reintroduced a vulnerability that could allow an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set during execve(2) execution (Red Hat Bugzilla).
An attacker with access to programs containing inheritable file capabilities could potentially elevate those capabilities to the permitted set when execve(2) runs, potentially leading to privilege escalation (Red Hat Bugzilla).
The issue has been addressed in Red Hat OpenShift Container Platform 4.12 through the security advisory RHSA-2022:7398. Users should upgrade to the patched versions to mitigate this vulnerability (Red Hat Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."