Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

False positives from C-0086 #312

Open
craigbox opened this issue Feb 20, 2023 · 3 comments
Open

False positives from C-0086 #312

craigbox opened this issue Feb 20, 2023 · 3 comments
Assignees
Labels
bug Something isn't working

Comments

@craigbox
Copy link
Contributor

Linux Kernel vulnerability CVE-2022-0492 may allow malicious code running inside container to escape container isolation and gain root privileges on the entire node. When fixed Kernel version numbers will become available, this control will be modified to verify them and avoid false positive detections. This control identifies all the resources that don't deploy neither AppArmor nor SELinux, run as root or allow privileged escalation or have corresponding dangerous capabilities.

Have fixed kernel version numbers become available?

@dwertent
Copy link

@slashben What do you think about this issue?

@slashben
Copy link
Contributor

@slashben What do you think about this issue?

I have checked the affected versions table at NVD. Seems like a very complex thing to manage from rego.

Maybe we should remove this control while we decided how to handle this properly.

@matthyx matthyx moved this to Triage in Kubescaping Aug 18, 2024
@matthyx matthyx moved this from Triage to High Priority in Kubescaping Sep 17, 2024
@matthyx matthyx added the bug Something isn't working label Sep 17, 2024
@Oshratn
Copy link
Contributor

Oshratn commented Sep 30, 2024

Decision:
Will be removed from the control list (and documentation) to be raplaced in the future with: host vulnerbality scanning.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
Status: High Priority
Development

No branches or pull requests

6 participants