HIGH 8.4 Microsoft
CVE-2022-1117
A vulnerability was found in fapolicyd. The vulnerability occurs due to an assumption on how glibc names the runtime linker a build time regular expression may not correctly detect the runtime linker. The consequence is that the pattern detection for applications launched by the run time linker may fail to detect the pattern and allow execution.
Microsoft Security Update 2022-Aug: A vulnerability was found in fapolicyd. The vulnerability occurs due to an assumption on how glibc names the runtime linker a build time regular expression may not correctly detect the runtime linker. The consequence is that the pattern detection for applications launched by the run time linker may fail to detect the pattern and allow execution.
Affected Products
- cbl2 fapolicyd 1.3.2-1 on CBL Mariner 2.0
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-1117
- https://nvd.nist.gov/vuln/detail/CVE-2022-1117
This high severity vulnerability with a CVSS score of 8.4 was published on 2022-08-09 via Microsoft. Affected: cbl2 fapolicyd 1.3.2-1 on CBL Mariner 2.0.
vulnfeed aggregates 9119 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.