Lucene search

K
ubuntucveUbuntu.comUB:CVE-2022-31214
HistoryJun 09, 2022 - 12:00 a.m.

CVE-2022-31214

2022-06-0900:00:00
ubuntu.com
ubuntu.com
14
firejail
privilege context switching
linux user namespace

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

5.1%

A Privilege Context Switching issue was discovered in join.c in Firejail
0.9.68. By crafting a bogus Firejail container that is accepted by the
Firejail setuid-root program as a join target, a local attacker can enter
an environment in which the Linux user namespace is still the initial user
namespace, the NO_NEW_PRIVS prctl is not activated, and the entered mount
namespace is under the attacker’s control. In this way, the filesystem
layout can be adjusted to gain root privileges through execution of
available setuid-root binaries such as su or sudo.

Bugs

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

5.1%