Vulnerability Description
The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190 advisory included an incorrect version of podman missing the fix for CVE-2020-8945, which was previously fixed via RHSA-2020:2117. This issue could possibly be used to crash or cause potential code execution in Go applications that use the Go GPGME wrapper library, under certain conditions, during GPG signature verification.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Enterprise Linux Server | 7.0 |
| Redhat | Enterprise Linux Workstation | 7.0 |
| Podman Project | Podman | 1.6.4-32.el7_9 |
Related Weaknesses (CWE)
References
- https://access.redhat.com/security/cve/CVE-2022-2738Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2116923Issue TrackingVendor Advisory
- https://access.redhat.com/security/cve/CVE-2022-2738Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2116923Issue TrackingVendor Advisory
FAQ
What is CVE-2022-2738?
CVE-2022-2738 is a vulnerability with a CVSS score of 7.5 (HIGH). The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190 advisory included an incorrect version of podman missing the fix for CVE-2020-8945, which was previously fixe...
How severe is CVE-2022-2738?
CVE-2022-2738 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-2738?
Check the references section above for vendor advisories and patch information. Affected products include: Redhat Enterprise Linux Server, Redhat Enterprise Linux Workstation, Podman Project Podman.