<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-09T17:06:38.005079+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2022-29162</id>
    <title>CVE-2022-29162 — Incorrect Default Permissions in runc</title>
    <updated>2026-10-09T17:06:38.022667+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> opencontainers runc</p>
<p>runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. A bug was found in runc prior to version 1.1.2 where `runc exec --cap` created processes with non-empty inheritable Linux process capabilities, creating an atypical Linux environment and enabling programs with inheritable file capabilities to elevate those capabilities to the permitted set during execve(2). This bug did not affect the container security sandbox as the inheritable set never contained more capabilities than were included in the container's bounding set. This bug has been fixed in runc 1.1.2. This fix changes `runc exec --cap` behavior such that the additional capabilities granted to the process being executed (as specified via `--cap` arguments) do not include inheritable capabilities. In addition, `runc spec` is changed to not set any inheritable capabilities in the created example OCI spec (`config.json`) file.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2022-29162"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/usn-6088-2</id>
    <title>USN-6088-2 — runc vulnerabilities</title>
    <updated>2026-10-09T17:06:38.022755+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: runc</p>
<p>USN-6088-1 fixed vulnerabilities in runC. This update provides
the corresponding updates for Ubuntu 16.04 LTS.</p>
<p>It was discovered that runC incorrectly performed access control when
mounting /proc to non-directories. An attacker could possibly use
this issue to escalate privileges.
(CVE-2019-19921)</p>
<p>Felix Wilhelm discovered that runC incorrecly handled netlink 
messages. An attacker could possibly use
this issue to escalate privileges. (CVE-2021-43784)</p>
<p>Andrew G. Morgan discovered that runC incorrectly set
inherited process capabilities inside the container.
An attacker could possibly use this issue to
escalate privileges. (CVE-2022-29162)</p>
<p>Original advisory details:</p>
<p>It was discovered that runC incorrectly made /sys/fs/cgroup
 writable when in rootless mode. An attacker could possibly
 use this issue to escalate privileges. (CVE-2023-25809)
 
 It was discovered that runC incorrectly performed access control when
 mounting /proc to non-directories. An attacker could possibly use
 this issue to escalate privileges. (CVE-2023-27561)
 
 It was discovered that runC incorrectly handled /proc and 
 /sys mounts inside a container. An attacker could possibly
 use this issue to bypass AppArmor, and potentially SELinux.
 (CVE-2023-28642)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/usn-6088-2"/>
  </entry>
</feed>
