Advisories ยป MGASA-2022-0117

Updated docker packages fix security vulnerability

Publication date: 28 Mar 2022
Modification date: 28 Mar 2022
Type: security
Affected Mageia releases : 8
CVE: CVE-2022-24769

Description

Containers were incorrectly started with non-empty inheritable Linux
process capabilities, creating an atypical Linux environment and enabling
programs with inheritable file capabilities to elevate those capabilities
to the permitted set during 'execve(2)' (CVE-2022-24769)
                

References

SRPMS

8/core