Steven Murdoch’s Post

View profile for Steven Murdoch

Professor of Security Engineering at University College London

CVE IDs have been assigned to the negative-group vulnerability as affecting container runtimes Podman (CVE-2022-2989), Buildah (CVE-2022-2990) and CRI-O (CVE-2022-2995). Why multiple CVE IDs? Because the Open Containers Initiative (OCI) specification didn’t require the vulnerable behaviour, but just was sufficiently ambiguous as to allow it. Consequently the CVE IDs get associated with the vulnerable software and not the specification. https://lnkd.in/djihj-3b #kubernetes #kubernetessecurity #podman #crio #containers #containersecurity #containerd #buildah #docker

Vulnerability in Linux containers – investigation and mitigation

Vulnerability in Linux containers – investigation and mitigation

https://www.benthamsgaze.org

To view or add a comment, sign in

Explore topics