HIGH · 7.5

CVE-2022-2738

The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190 advisory included an incorrect version of podman missing the fix for CVE-2020-8945, which was previously fixe...

Vulnerability Description

The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190 advisory included an incorrect version of podman missing the fix for CVE-2020-8945, which was previously fixed via RHSA-2020:2117. This issue could possibly be used to crash or cause potential code execution in Go applications that use the Go GPGME wrapper library, under certain conditions, during GPG signature verification.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
RedhatEnterprise Linux Server7.0
RedhatEnterprise Linux Workstation7.0
Podman ProjectPodman1.6.4-32.el7_9

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-2738?

CVE-2022-2738 is a vulnerability with a CVSS score of 7.5 (HIGH). The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190 advisory included an incorrect version of podman missing the fix for CVE-2020-8945, which was previously fixe...

How severe is CVE-2022-2738?

CVE-2022-2738 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-2738?

Check the references section above for vendor advisories and patch information. Affected products include: Redhat Enterprise Linux Server, Redhat Enterprise Linux Workstation, Podman Project Podman.