Vulnerability DatabaseGHSA-c9cp-9c75-9v8c

GHSA-c9cp-9c75-9v8c
vulnerability analysis and mitigation

Overview

A bug was discovered in containerd where containers were incorrectly started with non-empty inheritable Linux process capabilities. The vulnerability, identified as GHSA-c9cp-9c75-9v8c (CVE-2022-24769), affected containerd versions <=1.5.10, 1.6.0, and 1.6.1, and was fixed in versions 1.5.11 and 1.6.2. The issue created an atypical Linux environment that could potentially allow for privilege escalation within containers (GitHub Advisory).

Technical details

The vulnerability stems from containers being started with non-empty inheritable Linux process capabilities, which enabled programs with inheritable file capabilities to elevate those capabilities to the permitted set during execve(2). This created an environment where unprivileged users and processes could gain inheritable file capabilities up to the container's bounding set when executing programs with specified file capabilities. The bug specifically impacted containers that use Linux users and groups for privilege separation inside the container (Containerd Advisory).

Impact

The primary impact was on containers using Linux users and groups for privilege separation. While the vulnerability allowed for capability elevation within the container's bounding set, it's important to note that the container security sandbox remained unaffected as the inheritable set never contained more capabilities than were included in the container's bounding set (GitHub Advisory).

Exploitability

The vulnerability could be exploited by unprivileged users and processes within affected containers to gain additional inheritable file capabilities up to the container's bounding set. This was particularly relevant in containers that included executable programs with inheritable file capabilities (Debian Security).

Mitigation and workarounds

The issue has been patched in containerd versions 1.5.11 and 1.6.2. Users are advised to update to these versions and must stop, delete, and recreate running containers for the inheritable capabilities to be reset. As a workaround, the container's entrypoint can be modified to use a utility like capsh(1) to drop inheritable capabilities before the primary process starts (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management