Cri-o: security regression of cve-2022-27652
CVE-2022-3466
Key Information:
- Vendor
Red Hat
- Vendor
- CVE Published:
- 15 September 2023
What is CVE-2022-3466?
The version of cri-o as released for Red Hat OpenShift Container Platform 4.9.48, 4.10.31, and 4.11.6 via RHBA-2022:6316, RHBA-2022:6257, and RHBA-2022:6658, respectively, included an incorrect version of cri-o missing the fix for CVE-2022-27652, which was previously fixed in OCP 4.9.41 and 4.10.12 via RHBA-2022:5433 and RHSA-2022:1600. This issue could allow an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs. For more details, see https://access.redhat.com/security/cve/CVE-2022-27652.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Red Hat OpenShift Container Platform 4.12 0:1.25.1-5.rhaos4.12.git6005903.el9
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved