podman: possible information disclosure and modification
Published Sep 13, 2022
7.1
HIGHCVSS 3.1
EPSS 0.32%
Description
An incorrect handling of the supplementary groups in the Podman container engine might lead to the sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to set access permissions and is able to execute a binary code in that container.
Affected products
- Vendor n/a Product Podman Defaultn/a
- Version no fixed version knownStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Podman | n/a |
|
Configuration 1
- n/a
Configuration 2
- 3.11
- 4.0
- 7.0
- 8.0
- 9.0
No data.
Red Hat Enterprise Linux 8
container-tools:4.0-8080020230217080101.8108cfbc
Fixed · RHSA-2023:2802
Red Hat Enterprise Linux 8
container-tools:rhel8-8070020221026183352.489fc8e9
Fixed · RHSA-2022:7822
Red Hat Enterprise Linux 9
buildah-1:1.27.0-2.el9
Fixed · RHSA-2022:8008
Red Hat Enterprise Linux 9
podman-2:4.2.0-7.el9_1
Fixed · RHSA-2022:8431
Red Hat OpenShift Container Platform 4.12
buildah-1:1.23.4-5.1.rhaos4.12.el8
Fixed · RHSA-2023:3613
Red Hat OpenShift Container Platform 4.12
conmon-2:2.1.2-4.rhaos4.12.el8
Fixed · RHSA-2023:3613
Red Hat OpenShift Container Platform 4.12
containernetworking-plugins-0:1.0.1-7.rhaos4.12.el8
Fixed · RHSA-2023:3613
Red Hat OpenShift Container Platform 4.12
kernel-0:4.18.0-372.59.1.el8_6
Fixed · RHSA-2023:3613
Red Hat OpenShift Container Platform 4.12
kernel-rt-0:4.18.0-372.59.1.rt7.217.el8_6
Fixed · RHSA-2023:3613
Red Hat OpenShift Container Platform 4.12
openshift-0:4.12.0-202306121916.p0.g8c21020.assembly.stream.el8
Fixed · RHSA-2023:3613
Red Hat OpenShift Container Platform 4.12
openshift-ansible-0:4.12.0-202306090942.p0.g74dc7b3.assembly.stream.el8
Fixed · RHSA-2023:3613
Red Hat OpenShift Container Platform 4.12
openshift-clients-0:4.12.0-202306090942.p0.g3c01edd.assembly.stream.el8
Fixed · RHSA-2023:3613
Red Hat OpenShift Container Platform 4.12
openshift-kuryr-0:4.12.0-202306140156.p0.g31dd228.assembly.stream.el8
Fixed · RHSA-2023:3613
Red Hat OpenShift Container Platform 4.12
openshift4-aws-iso-0:4.12.0-202306090942.p0.gd2acdd5.assembly.stream.el8
Fixed · RHSA-2023:3613
Red Hat OpenShift Container Platform 4.12
podman-3:4.2.0-6.1.rhaos4.12.el8
Fixed · RHSA-2023:3613
Red Hat OpenShift Container Platform 4.12
runc-3:1.1.6-4.rhaos4.12.el8
Fixed · RHSA-2023:3613
Red Hat OpenShift Container Platform 4.12
skopeo-2:1.9.4-3.1.rhaos4.12.el8
Fixed · RHSA-2023:3613
Red Hat Enterprise Linux 7
podman
Fix deferred
Red Hat Enterprise Linux 8
container-tools:3.0/podman
Not affected
Red Hat OpenShift Container Platform 3.11
podman
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | container-tools:4.0-8080020230217080101.8108cfbc | Fixed | RHSA-2023:2802 |
| Red Hat Enterprise Linux 8 | container-tools:rhel8-8070020221026183352.489fc8e9 | Fixed | RHSA-2022:7822 |
| Red Hat Enterprise Linux 9 | buildah-1:1.27.0-2.el9 | Fixed | RHSA-2022:8008 |
| Red Hat Enterprise Linux 9 | podman-2:4.2.0-7.el9_1 | Fixed | RHSA-2022:8431 |
| Red Hat OpenShift Container Platform 4.12 | buildah-1:1.23.4-5.1.rhaos4.12.el8 | Fixed | RHSA-2023:3613 |
| Red Hat OpenShift Container Platform 4.12 | conmon-2:2.1.2-4.rhaos4.12.el8 | Fixed | RHSA-2023:3613 |
| Red Hat OpenShift Container Platform 4.12 | containernetworking-plugins-0:1.0.1-7.rhaos4.12.el8 | Fixed | RHSA-2023:3613 |
| Red Hat OpenShift Container Platform 4.12 | kernel-0:4.18.0-372.59.1.el8_6 | Fixed | RHSA-2023:3613 |
| Red Hat OpenShift Container Platform 4.12 | kernel-rt-0:4.18.0-372.59.1.rt7.217.el8_6 | Fixed | RHSA-2023:3613 |
| Red Hat OpenShift Container Platform 4.12 | openshift-0:4.12.0-202306121916.p0.g8c21020.assembly.stream.el8 | Fixed | RHSA-2023:3613 |
| Red Hat OpenShift Container Platform 4.12 | openshift-ansible-0:4.12.0-202306090942.p0.g74dc7b3.assembly.stream.el8 | Fixed | RHSA-2023:3613 |
| Red Hat OpenShift Container Platform 4.12 | openshift-clients-0:4.12.0-202306090942.p0.g3c01edd.assembly.stream.el8 | Fixed | RHSA-2023:3613 |
| Red Hat OpenShift Container Platform 4.12 | openshift-kuryr-0:4.12.0-202306140156.p0.g31dd228.assembly.stream.el8 | Fixed | RHSA-2023:3613 |
| Red Hat OpenShift Container Platform 4.12 | openshift4-aws-iso-0:4.12.0-202306090942.p0.gd2acdd5.assembly.stream.el8 | Fixed | RHSA-2023:3613 |
| Red Hat OpenShift Container Platform 4.12 | podman-3:4.2.0-6.1.rhaos4.12.el8 | Fixed | RHSA-2023:3613 |
| Red Hat OpenShift Container Platform 4.12 | runc-3:1.1.6-4.rhaos4.12.el8 | Fixed | RHSA-2023:3613 |
| Red Hat OpenShift Container Platform 4.12 | skopeo-2:1.9.4-3.1.rhaos4.12.el8 | Fixed | RHSA-2023:3613 |
| Red Hat Enterprise Linux 7 | podman | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | container-tools:3.0/podman | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.11 | podman | Out of support scope | n/a |
github.com/containers/podman/v3
Go
Introduced 0 Fixed 3.0.1github.com/containers/podman/v4
Go
Introduced 0 Fixed 4.2.0
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/containers/podman/v3 | 0 | 3.0.1 |
| Go | github.com/containers/podman/v4 | 0 | 4.2.0 |
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
1 other source (Red Hat) ▾
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Jun 5, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (11 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 0.32% (0.00322) | 23.05th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.30% (0.00298) | 21.23th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.03% (0.00032) | 5.94th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.05% (0.00048) | 19.71th | v3 (v2023.03.01) |
| Jun 14, 2024 | 0.05% (0.00048) | 17.77th | v3 (v2023.03.01) |
| Apr 5, 2024 | 0.05% (0.00048) | 15.72th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.04% (0.00043) | 6.97th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.89% (0.00885) | 27.89th | v2 (v2022.01.01) |
| Feb 13, 2023 | 0.89% (0.00885) | 27.56th | v2 (v2022.01.01) |
| Feb 3, 2023 | 1.03% (0.01034) | 40.96th | v2 (v2022.01.01) |
| Sep 14, 2022 | 0.89% (0.00885) | 26.28th | v2 (v2022.01.01) |
References (12)
- https://access.redhat.com/errata/RHSA-2022:7822
- https://access.redhat.com/errata/RHSA-2022:8008
- https://access.redhat.com/errata/RHSA-2022:8431
- https://access.redhat.com/security/cve/CVE-2022-2989 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2121445 x_refsource_MISCExploitIssue TrackingPatchThird Party Advisory
- https://github.com/advisories/GHSA-4wjj-jwc9-2x96 Advisory
- https://github.com/containers/podman/pull/15618
- https://github.com/containers/podman/pull/15677
- https://github.com/containers/podman/pull/15696
- https://nvd.nist.gov/vuln/detail/CVE-2022-2989
- https://www.benthamsgaze.org/2022/08/22/vulnerability-in-linux-containers-investigation-and-mitigation x_refsource_MISCExploitThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-2989
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2022:7822 | ||
| https://access.redhat.com/errata/RHSA-2022:8008 | ||
| https://access.redhat.com/errata/RHSA-2022:8431 | ||
| https://access.redhat.com/security/cve/CVE-2022-2989 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2121445 | x_refsource_MISCExploitIssue TrackingPatchThird Party Advisory | |
| https://github.com/advisories/GHSA-4wjj-jwc9-2x96 | Advisory | |
| https://github.com/containers/podman/pull/15618 | ||
| https://github.com/containers/podman/pull/15677 | ||
| https://github.com/containers/podman/pull/15696 | ||
| https://nvd.nist.gov/vuln/detail/CVE-2022-2989 | ||
| https://www.benthamsgaze.org/2022/08/22/vulnerability-in-linux-containers-investigation-and-mitigation | x_refsource_MISCExploitThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2022-2989 |
Change history (0)
No recorded changes yet.