Incorrect Default Permissions in runc
Published May 17, 2022
7.8
HIGHCVSS 3.1
EPSS 0.39%
Description
runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. A bug was found in runc prior to version 1.1.2 where `runc exec --cap` created processes with non-empty inheritable Linux process capabilities, creating an atypical Linux environment and enabling programs with inheritable file capabilities to elevate those capabilities to the permitted set during execve(2). This bug did not affect the container security sandbox as the inheritable set never contained more capabilities than were included in the container's bounding set. This bug has been fixed in runc 1.1.2. This fix changes `runc exec --cap` behavior such that the additional capabilities granted to the process being executed (as specified via `--cap` arguments) do not include inheritable capabilities. In addition, `runc spec` is changed to not set any inheritable capabilities in the created example OCI spec (`config.json`) file.
Affected products
-
- Version < 1.1.2StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Opencontainers | Runc | n/a |
|
Configuration 1
- < 1.1.2
Configuration 2
- 34
- 35
- 36
No data.
Red Hat Enterprise Linux 8
container-tools:4.0-8070020220830101436.39077419
Fixed · RHSA-2022:7469
Red Hat Enterprise Linux 8
container-tools:rhel8-8070020220929222448.39077419
Fixed · RHSA-2022:7457
Red Hat Enterprise Linux 9
runc-4:1.1.4-1.el9
Fixed · RHSA-2022:8090
Red Hat OpenShift Container Platform 4.11
runc-3:1.1.2-1.rhaos4.11.el8
Fixed · RHSA-2022:5068
Red Hat Enterprise Linux 7
runc
Out of support scope
Red Hat Enterprise Linux 8
container-tools:2.0/runc
Fix deferred
Red Hat Enterprise Linux 8
container-tools:3.0/runc
Fix deferred
Red Hat OpenShift Container Platform 3.11
runc
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | container-tools:4.0-8070020220830101436.39077419 | Fixed | RHSA-2022:7469 |
| Red Hat Enterprise Linux 8 | container-tools:rhel8-8070020220929222448.39077419 | Fixed | RHSA-2022:7457 |
| Red Hat Enterprise Linux 9 | runc-4:1.1.4-1.el9 | Fixed | RHSA-2022:8090 |
| Red Hat OpenShift Container Platform 4.11 | runc-3:1.1.2-1.rhaos4.11.el8 | Fixed | RHSA-2022:5068 |
| Red Hat Enterprise Linux 7 | runc | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | container-tools:2.0/runc | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | container-tools:3.0/runc | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 3.11 | runc | Out of support scope | n/a |
github.com/opencontainers/runc
Go
Introduced 0 Fixed 1.1.2
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/opencontainers/runc | 0 | 1.1.2 |
Remediation
Red Hat statement
This issue is rated as low severity as the vulnerability can only result in atypical linux environment,and it's complex exploitation only results in minimal impact on system confidentiality, integrity, and availability in typical environments.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
2 other sources (GHSA, Red Hat) ▾
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
No CVSS v3.0 score for this CVE.
AV:L/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Apr 23, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (14 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.39% (0.00393) | 31.08th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.39% (0.00386) | 30.13th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.10% (0.00101) | 25.57th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.04% (0.00045) | 16.02th | v3 (v2023.03.01) |
| Jun 13, 2024 | 0.04% (0.00045) | 14.17th | v3 (v2023.03.01) |
| Aug 22, 2023 | 0.04% (0.00045) | 12.16th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.04% (0.00042) | 5.63th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.03% (0.01034) | 41.69th | v2 (v2022.01.01) |
| Feb 22, 2023 | 1.03% (0.01034) | 41.41th | v2 (v2022.01.01) |
| Dec 29, 2022 | 2.01% (0.02008) | 78.73th | v2 (v2022.01.01) |
| Dec 3, 2022 | 1.03% (0.01034) | 40.60th | v2 (v2022.01.01) |
| Jun 1, 2022 | 1.03% (0.01034) | 38.59th | v2 (v2022.01.01) |
| May 30, 2022 | 0.95% (0.00950) | 29.30th | v2 (v2022.01.01) |
| May 18, 2022 | 0.89% (0.00890) | 27.24th | v2 (v2022.01.01) |
References (15)
- https://access.redhat.com/security/cve/CVE-2022-29162 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2086398 Issue Tracking
- https://github.com/advisories/GHSA-f3fp-gc8g-vw66 Advisory
- https://github.com/opencontainers/runc/commit/d04de3a9b72d7a2455c1885fc75eb36d02cd17b5 PatchThird Party Advisory
- https://github.com/opencontainers/runc/releases/tag/v1.1.2 Release NotesThird Party Advisory
- https://github.com/opencontainers/runc/security/advisories/GHSA-f3fp-gc8g-vw66 Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/03/msg00023.html mailing-list
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AVPZBV7ISA7QKRPTC7ZXWKMIQI2HZEBB/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/D77CKD3AXPMU4PMQIQI5Q74SI4JATNND/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GPQU4YC4AAY54JDXGDQHJEYKSXXG5T2Y/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AVPZBV7ISA7QKRPTC7ZXWKMIQI2HZEBB/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/D77CKD3AXPMU4PMQIQI5Q74SI4JATNND/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GPQU4YC4AAY54JDXGDQHJEYKSXXG5T2Y/
- https://nvd.nist.gov/vuln/detail/CVE-2022-29162
- https://www.cve.org/CVERecord?id=CVE-2022-29162
Change history (0)
No recorded changes yet.