Bug 2124794 (CVE-2022-36067)
Summary: | CVE-2022-36067 vm2: Sandbox Escape in vm2 | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Sandipan Roy <saroy> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | urgent | Docs Contact: | |
Priority: | urgent | ||
Version: | unspecified | CC: | gparvin, jramanat, njean, pahickey, stcannon |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | vm2 3.9.11 | Doc Type: | If docs needed, set a value |
Doc Text: |
A flaw was found in the vm2 sandbox when running untrusted code, as the sandbox setup does not manage proper exception handling. This flaw allows an attacker to bypass the sandbox protections and gain remote code execution on the hypervisor host or the host which is running the sandbox.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | 2022-11-28 05:25:20 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 2124956, 2124957, 2124958, 2124983, 2124984 | ||
Bug Blocks: | 2124795 |
Description
Sandipan Roy
2022-09-07 06:38:10 UTC
This issue has been addressed in the following products: multicluster engine for Kubernetes 2.0 for RHEL 8 Via RHSA-2022:6422 https://access.redhat.com/errata/RHSA-2022:6422 This issue has been addressed in the following products: multicluster engine for Kubernetes 2.1 for RHEL 8 Via RHSA-2022:6424 https://access.redhat.com/errata/RHSA-2022:6424 This issue has been addressed in the following products: Red Hat Advanced Cluster Management for Kubernetes 2.6 for RHEL 8 Via RHSA-2022:6427 https://access.redhat.com/errata/RHSA-2022:6427 This issue has been addressed in the following products: Red Hat Advanced Cluster Management for Kubernetes 2.5 for RHEL 8 Via RHSA-2022:6507 https://access.redhat.com/errata/RHSA-2022:6507 This issue has been addressed in the following products: Red Hat Advanced Cluster Management for Kubernetes 2.4 for RHEL 8 Via RHSA-2022:6696 https://access.redhat.com/errata/RHSA-2022:6696 This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2022-36067 |