
Cloud Vulnerability DB
A community-led vulnerabilities database
A bug was discovered in containerd where containers were incorrectly started with non-empty inheritable Linux process capabilities. The vulnerability, identified as GHSA-c9cp-9c75-9v8c (CVE-2022-24769), affected containerd versions <=1.5.10, 1.6.0, and 1.6.1, and was fixed in versions 1.5.11 and 1.6.2. The issue created an atypical Linux environment that could potentially allow for privilege escalation within containers (GitHub Advisory).
The vulnerability stems from containers being started with non-empty inheritable Linux process capabilities, which enabled programs with inheritable file capabilities to elevate those capabilities to the permitted set during execve(2). This created an environment where unprivileged users and processes could gain inheritable file capabilities up to the container's bounding set when executing programs with specified file capabilities. The bug specifically impacted containers that use Linux users and groups for privilege separation inside the container (Containerd Advisory).
The primary impact was on containers using Linux users and groups for privilege separation. While the vulnerability allowed for capability elevation within the container's bounding set, it's important to note that the container security sandbox remained unaffected as the inheritable set never contained more capabilities than were included in the container's bounding set (GitHub Advisory).
The vulnerability could be exploited by unprivileged users and processes within affected containers to gain additional inheritable file capabilities up to the container's bounding set. This was particularly relevant in containers that included executable programs with inheritable file capabilities (Debian Security).
The issue has been patched in containerd versions 1.5.11 and 1.6.2. Users are advised to update to these versions and must stop, delete, and recreate running containers for the inheritable capabilities to be reset. As a workaround, the container's entrypoint can be modified to use a utility like capsh(1) to drop inheritable capabilities before the primary process starts (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."