CVE-2022-2995

Publication date 19 September 2022

Last updated 25 August 2025


Ubuntu priority

Cvss 3 Severity Score

7.1 · High

Score breakdown

Description

Incorrect handling of the supplementary groups in the CRI-O container engine might lead to sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to set access permissions and is able to execute a binary code in that container.

Status

Package Ubuntu Release Status
cri-o 24.04 LTS noble Not in release
22.04 LTS jammy Not in release
20.04 LTS focal Not in release

Severity score breakdown

CVSS version: CVSS v3.0

Base score 7.1 · High

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N


Access our resources on patching vulnerabilities