SB2021030204 - Red Hat Enterprise Linux 7 Extras update for podman
Published: March 2, 2021
Security Bulletin ID
SB2021030204
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Local access
Highest impact
Code execution
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Security restrictions bypass (CVE-ID: CVE-2021-20188)
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to file permissions for non-root users running in a privileged container are not correctly checked. A local low-privileged user inside the container can access arbitrary files in the container despite file permissions, e.g. even files owned by the root user inside the container are accessible.
Successful exploitation of the vulnerability may allow a local user to escalate privileges on the system.
Remediation
Install update from vendor's website.