MGASA-2022-0192
Advisory lineage Upstream: 1 Downstream: 0
Upstream
Published: 21 May 2022, 08:50
Last modified:16 Apr 2026, 04:23
Vulnerability Summary
Overall Risk (default)
minimal
0/100 CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
21 May 2022, 08:50
Published
Vulnerability first disclosed
16 Apr 2026, 04:23
Last Modified
Vulnerability information updated
Description
Updated opencontainers-runc packages fix security vulnerability A bug was found in runc where runc exec --cap executed processes with non-empty inheritable Linux process capabilities, creating an atypical Linux environment and enabling programs with inheritable file capabilities to elevate those capabilities to the permitted set during execve(2). This bug did not affect the container security sandbox as the inheritable set never contained more capabilities than were included in the container's bounding set. (CVE-2022-29162)
Affected Systems
- mageia•opencontainers-runc
< 1.1.2-2.mga8