REDHAT-BUG-2121445: Low severity podman vulnerability
An incorrect handling of the supplementary groups in the Podman container engine might lead to the sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to set access permissions and is able to execute a binary code in that container.
Reference:
https://www.benthamsgaze.org/2022/08/22/vulnerability-in-linux-containers-investigation-and-mitigation/
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2121445?
REDHAT-BUG-2121445 has a high severity due to the potential for sensitive information disclosure and data modification.
How do I fix REDHAT-BUG-2121445?
To fix REDHAT-BUG-2121445, ensure you are running the latest version of Podman where the vulnerability has been addressed.
What causes the vulnerability identified as REDHAT-BUG-2121445?
REDHAT-BUG-2121445 is caused by incorrect handling of supplementary groups in the Podman container engine.
Who is affected by REDHAT-BUG-2121445?
Any user or system that utilizes the Podman container engine and configurations that involve supplementary groups is at risk due to REDHAT-BUG-2121445.
Can REDHAT-BUG-2121445 be exploited remotely?
No, REDHAT-BUG-2121445 requires direct access to the affected container for exploitation.