CVE-2022-31214 is a privilege context switching vulnerability in Firejail 0.9.68, affecting various distributions including Debian and Fedora. A local attacker can craft a malicious Firejail container to enter an environment with the initial user namespace, no NO_NEW_PRIVS prctl, and attacker-controlled mount namespace. This allows for filesystem manipulation to execute setuid-root binaries like su or sudo, leading to root privilege escalation. The vulnerability has a CVSS score of 7.8 (High) due to its low attack complexity and high impact on confidentiality, integrity, and availability. Currently, there is no known exploit intelligence, Metasploit modules, or public exploit code, and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.9.68CPE matchmatch criteria | cpe:2.3:a:firejail_project:firejail:0.9.68:*:*:*:*:*:*:* | ||
35CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:* | ||
36CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:* | ||
37CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.