Database/Container, Kubernetes & orchestration
Docker / moby: Containers started with non-empty inheritable capabilities
CVSS 5.9CVE-2022-24769Container, Kubernetes & orchestrationcurated
Impact
Containers started with non-empty inheritable capabilities; unexpected privilege retention on setuid binaries
Who can reach it
Any tenant workload
What to do
Upgrade Docker Engine / moby; restart containers
References
Related entries
- Docker / moby: DNS requests from an internal network can be forwarded to external resolvers, leaking data outCVE-2024-29018 · Docker / mobyMedium
- Docker / moby: Default OCI spec does not mask /proc/acpi, so a container can change host hardware stateCVE-2018-10892 · Docker / mobyMedium
- Docker / moby: Supplementary groups not set up properlyCVE-2022-36109 · Docker / mobyMedium
- Docker / moby: On firewalld reload, published container ports become reachable from outside despite the intendedCVE-2025-54388 · Docker / mobyMedium
- Docker / moby: IPv6 not disabled on interfaces where it should beCVE-2024-32473 · Docker / mobyMedium
- Docker / moby: Related firewalld handling defect affecting Moby port exposureCVE-2025-54410 · Docker / mobyLow
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.