47ecc2
From ed485db1465d67f0215c27529c57a76a1daf5135 Mon Sep 17 00:00:00 2001
47ecc2
From: Giuseppe Scrivano <gscrivan@redhat.com>
47ecc2
Date: Mon, 28 Feb 2022 11:05:18 +0100
47ecc2
Subject: [PATCH 1/2] spec: do not set inheritable capabilities
47ecc2
47ecc2
Closes: CVE-2022-27650
47ecc2
47ecc2
Signed-off-by: Giuseppe Scrivano <gscrivan@redhat.com>
47ecc2
(cherry picked from commit b847d146d496c9d7beba166fd595488e85488562)
47ecc2
---
47ecc2
 src/libcrun/container.c | 3 ---
47ecc2
 1 file changed, 3 deletions(-)
47ecc2
47ecc2
diff --git a/src/libcrun/container.c b/src/libcrun/container.c
47ecc2
index d3fb017..1e3f3e6 100644
47ecc2
--- a/src/libcrun/container.c
47ecc2
+++ b/src/libcrun/container.c
47ecc2
@@ -128,9 +128,6 @@ static char spec_file[] = "\
47ecc2
 				\"CAP_NET_BIND_SERVICE\"\n\
47ecc2
 			],\n\
47ecc2
 			\"inheritable\": [\n\
47ecc2
-				\"CAP_AUDIT_WRITE\",\n\
47ecc2
-				\"CAP_KILL\",\n\
47ecc2
-				\"CAP_NET_BIND_SERVICE\"\n\
47ecc2
 			],\n\
47ecc2
 			\"permitted\": [\n\
47ecc2
 				\"CAP_AUDIT_WRITE\",\n\
47ecc2
-- 
47ecc2
2.35.1
47ecc2