Back

HIGH

Incorrect Default Permissions in runc

Published May 17, 2022

Description

runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. A bug was found in runc prior to version 1.1.2 where `runc exec --cap` created processes with non-empty inheritable Linux process capabilities, creating an atypical Linux environment and enabling programs with inheritable file capabilities to elevate those capabilities to the permitted set during execve(2). This bug did not affect the container security sandbox as the inheritable set never contained more capabilities than were included in the container's bounding set. This bug has been fixed in runc 1.1.2. This fix changes `runc exec --cap` behavior such that the additional capabilities granted to the process being executed (as specified via `--cap` arguments) do not include inheritable capabilities. In addition, `runc spec` is changed to not set any inheritable capabilities in the created example OCI spec (`config.json`) file.

Affected products

Remediation

Red Hat statement

This issue is rated as low severity as the vulnerability can only result in atypical linux environment,and it's complex exploitation only results in minimal impact on system confidentiality, integrity, and availability in typical environments.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Metrics

References (15)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published May 17, 2022
Updated Apr 23, 2025
Reserved Apr 13, 2022
CISA Vulnrichment
Updated Apr 23, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date May 13, 2022
GHSA-F3FP-GC8G-VW66