buildah: possible information disclosure and modification
Published Sep 13, 2022
7.1
HIGHCVSS 3.1
EPSS 0.35%
Description
An incorrect handling of the supplementary groups in the Buildah container engine might lead to the sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to set access permissions and is able to execute a binary code in that container.
Affected products
- Vendor n/a Product Buildah Defaultunknown
Affected
- no fixed version known
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| n/a | Buildah | unknown | Affected
|
Configuration 1
- < 1.27.1
Configuration 2
- 4.0
- 7.0
- 8.0
- 9.0
No data.
Red Hat Enterprise Linux 8
container-tools:rhel8-8070020220929222448.39077419
Fixed · RHSA-2022:7457
Red Hat Enterprise Linux 8
container-tools:rhel8-8070020221026183352.489fc8e9
Fixed · RHSA-2022:7822
Red Hat Enterprise Linux 9
buildah-1:1.27.0-2.el9
Fixed · RHSA-2022:8008
Red Hat Enterprise Linux 9
podman-2:4.2.0-7.el9_1
Fixed · RHSA-2022:8431
Red Hat OpenShift Container Platform 4.13
buildah-1:1.29.1-1.rhaos4.13.el9
Fixed · RHSA-2023:1325
Red Hat Enterprise Linux 7
buildah
Fix deferred
Red Hat Enterprise Linux 8
container-tools:3.0/buildah
Fix deferred
Red Hat Enterprise Linux 8
container-tools:4.0/buildah
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | container-tools:rhel8-8070020220929222448.39077419 | Fixed | RHSA-2022:7457 |
| Red Hat Enterprise Linux 8 | container-tools:rhel8-8070020221026183352.489fc8e9 | Fixed | RHSA-2022:7822 |
| Red Hat Enterprise Linux 9 | buildah-1:1.27.0-2.el9 | Fixed | RHSA-2022:8008 |
| Red Hat Enterprise Linux 9 | podman-2:4.2.0-7.el9_1 | Fixed | RHSA-2022:8431 |
| Red Hat OpenShift Container Platform 4.13 | buildah-1:1.29.1-1.rhaos4.13.el9 | Fixed | RHSA-2023:1325 |
| Red Hat Enterprise Linux 7 | buildah | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | container-tools:3.0/buildah | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | container-tools:4.0/buildah | Fix deferred | n/a |
github.com/containers/buildah
Go
Introduced 0 Fixed 1.27.1
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/containers/buildah | 0 | 1.27.1 |
Remediation
No remediation recorded yet.
References (10)
- https://access.redhat.com/security/cve/CVE-2022-2990 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2121453 x_refsource_MISCExploitIssue TrackingPatchThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-6800 Advisory
- https://github.com/advisories/GHSA-fjm8-m7m6-2fjp Advisory
- https://github.com/containers/buildah/commit/4a8bf740e862f2438279c6feee2ea59ddf0cda0b
- https://github.com/containers/buildah/pull/4200
- https://nvd.nist.gov/vuln/detail/CVE-2022-2990
- https://pkg.go.dev/vuln/GO-2022-1008
- https://www.benthamsgaze.org/2022/08/22/vulnerability-in-linux-containers-investigation-and-mitigation/ x_refsource_MISCExploitThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-2990
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-2990 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2121453 | x_refsource_MISCExploitIssue TrackingPatchThird Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-6800 | Advisory | |
| https://github.com/advisories/GHSA-fjm8-m7m6-2fjp | Advisory | |
| https://github.com/containers/buildah/commit/4a8bf740e862f2438279c6feee2ea59ddf0cda0b | ||
| https://github.com/containers/buildah/pull/4200 | ||
| https://nvd.nist.gov/vuln/detail/CVE-2022-2990 | ||
| https://pkg.go.dev/vuln/GO-2022-1008 | ||
| https://www.benthamsgaze.org/2022/08/22/vulnerability-in-linux-containers-investigation-and-mitigation/ | x_refsource_MISCExploitThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2022-2990 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub