{"id":"CVE-2022-27652","aliases":["GHSA-4hj2-r2pm-3hc6","GO-2022-0426"],"url":"https://o3.security/vulnerability/CVE-2022-27652","summary":"Incorrect Default Permissions in CRI-O","details":"A flaw was found in cri-o, where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs.","published":"2022-04-18T16:20:29Z","modified":"2026-08-12T03:51:26.742971400Z","cvss":{"score":4.8,"severity":"MEDIUM","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/cri-o/cri-o","fixedVersion":"1.24.0"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/27xxx/CVE-2022-27652.json"},{"type":"ADVISORY","url":"https://github.com/cri-o/cri-o/security/advisories/GHSA-4hj2-r2pm-3hc6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-27652"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2066839"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:26.742971400Z"}}