CVE-2024-1753
Vulnerability Summary
Timeline
Description
A flaw was found in Buildah (and subsequently Podman Build) which allows containers to mount arbitrary locations on the host filesystem into build containers. A malicious Containerfile can use a dummy image with a symbolic link to the root filesystem as a mount source and cause the mount operation to mount the host root filesystem inside the RUN step. The commands inside the RUN step will then have read-write access to the host filesystem, allowing for full container escape at build time.
CVSS Metrics
- v4.0•MEDIUM•Score: 6.3CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H
- v3.1•HIGH•Score: 8.6CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
EPSS Trends
Current EPSS score: 0.49%• Percentile: 41%
Techniques & Countermeasures
- CWE-59•Improper Link Resolution Before File Access ('Link Following')
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Affected Systems
- chainguard•podman
< 0
- chainguard•podman-doc
< 0
- wolfi•podman
< 0
- wolfi•podman-doc
< 0
- debian•golang-github-containers-buildah
all | all | < 1.33.7+ds1-1 | < 1.33.7+ds1-1
- github.com/containers•buildah
< 1.35.1 | ≥ 1.35.0, < 1.35.1 | ≥ 1.34.0, < 1.34.3 | ≥ 1.33.0, < 1.33.7 | ≥ 1.25.0, < 1.27.4 | ≥ 1.24.0, < 1.24.7 | ≥ 1.28.0, < 1.29.3 | ≥ 1.30.0, < 1.31.5 | ≥ 1.32.0, < 1.32.3
- github.com/containers/podman•v4
< 4.9.4
- github.com/containers/podman•v5
< 5.0.1
- redhat•aardvark-dns
< 2:1.0.1-38.module+el8.9.0+21673+408ce8ab | < 2:1.0.1-40.module+el8.6.0+21745+f5f35196 | < 2:1.0.1-29.module+el8.6.0+21719+09b58c97 | < 2:1.7.0-1.module+el8.9.0+21697+6a5e98e7
- redhat•buildah
< 1:1.31.5-1.el9_3 | < 1:1.29.3-1.el9_2 | < 1:1.26.7-1.el9_0 | < 1:1.24.7-1.module+el8.9.0+21673+408ce8ab | < 1:1.26.7-1.module+el8.6.0+21745+f5f35196 | < 1:1.24.7-1.module+el8.6.0+21719+09b58c97 | < 1:1.31.5-1.module+el8.9.0+21697+6a5e98e7
- redhat•buildah-debuginfo
< 1:1.31.5-1.el9_3 | < 1:1.29.3-1.el9_2 | < 1:1.26.7-1.el9_0 | < 1:1.24.7-1.module+el8.9.0+21673+408ce8ab | < 1:1.26.7-1.module+el8.6.0+21745+f5f35196 | < 1:1.24.7-1.module+el8.6.0+21719+09b58c97 | < 1:1.31.5-1.module+el8.9.0+21697+6a5e98e7
- redhat•buildah-debugsource
< 1:1.31.5-1.el9_3 | < 1:1.29.3-1.el9_2 | < 1:1.26.7-1.el9_0 | < 1:1.24.7-1.module+el8.9.0+21673+408ce8ab | < 1:1.26.7-1.module+el8.6.0+21745+f5f35196 | < 1:1.24.7-1.module+el8.6.0+21719+09b58c97 | < 1:1.31.5-1.module+el8.9.0+21697+6a5e98e7
- redhat•buildah-tests
< 1:1.31.5-1.el9_3 | < 1:1.29.3-1.el9_2 | < 1:1.26.7-1.el9_0 | < 1:1.24.7-1.module+el8.9.0+21673+408ce8ab | < 1:1.26.7-1.module+el8.6.0+21745+f5f35196 | < 1:1.24.7-1.module+el8.6.0+21719+09b58c97 | < 1:1.31.5-1.module+el8.9.0+21697+6a5e98e7
- redhat•buildah-tests-debuginfo
< 1:1.31.5-1.el9_3 | < 1:1.29.3-1.el9_2 | < 1:1.26.7-1.el9_0 | < 1:1.24.7-1.module+el8.9.0+21673+408ce8ab | < 1:1.26.7-1.module+el8.6.0+21745+f5f35196 | < 1:1.24.7-1.module+el8.6.0+21719+09b58c97 | < 1:1.31.5-1.module+el8.9.0+21697+6a5e98e7
- redhat•cockpit-podman
< 0:46-1.module+el8.9.0+21673+408ce8ab | < 0:49.1-1.module+el8.6.0+21745+f5f35196 | < 0:43-1.module+el8.6.0+21719+09b58c97 | < 0:75-1.module+el8.9.0+21697+6a5e98e7
- redhat•conmon
< 2:2.1.4-2.module+el8.9.0+21673+408ce8ab | < 2:2.1.4-1.module+el8.6.0+21745+f5f35196 | < 2:2.1.0-1.module+el8.6.0+21719+09b58c97 | < 3:2.1.8-1.module+el8.9.0+21697+6a5e98e7
- redhat•conmon-debuginfo
< 2:2.1.4-2.module+el8.9.0+21673+408ce8ab | < 2:2.1.4-1.module+el8.6.0+21745+f5f35196 | < 2:2.1.0-1.module+el8.6.0+21719+09b58c97 | < 3:2.1.8-1.module+el8.9.0+21697+6a5e98e7
- redhat•conmon-debugsource
< 2:2.1.4-2.module+el8.9.0+21673+408ce8ab | < 2:2.1.4-1.module+el8.6.0+21745+f5f35196 | < 2:2.1.0-1.module+el8.6.0+21719+09b58c97 | < 3:2.1.8-1.module+el8.9.0+21697+6a5e98e7
- redhat•container-selinux
< 2:2.205.0-3.module+el8.9.0+21673+408ce8ab | < 2:2.189.0-1.module+el8.6.0+21745+f5f35196 | < 2:2.178.0-1.module+el8.6.0+21719+09b58c97 | < 2:2.229.0-1.module+el8.9.0+21697+6a5e98e7
- redhat•containernetworking-plugins
< 1:1.1.1-6.module+el8.9.0+21673+408ce8ab | < 1:1.1.1-4.module+el8.6.0+21745+f5f35196 | < 0:1.0.1-1.module+el8.6.0+21719+09b58c97 | < 1:1.3.0-8.module+el8.9.0+21697+6a5e98e7
- redhat•containernetworking-plugins-debuginfo
< 1:1.1.1-6.module+el8.9.0+21673+408ce8ab | < 1:1.1.1-4.module+el8.6.0+21745+f5f35196 | < 0:1.0.1-1.module+el8.6.0+21719+09b58c97 | < 1:1.3.0-8.module+el8.9.0+21697+6a5e98e7
- redhat•containernetworking-plugins-debugsource
< 1:1.1.1-6.module+el8.9.0+21673+408ce8ab | < 1:1.1.1-4.module+el8.6.0+21745+f5f35196 | < 0:1.0.1-1.module+el8.6.0+21719+09b58c97 | < 1:1.3.0-8.module+el8.9.0+21697+6a5e98e7
- redhat•containers-common
< 2:1-38.module+el8.9.0+21673+408ce8ab | < 2:1-40.module+el8.6.0+21745+f5f35196 | < 2:1-29.module+el8.6.0+21719+09b58c97 | < 2:1-71.module+el8.9.0+21697+6a5e98e7
- redhat•crit
< 0:3.15-3.module+el8.9.0+21673+408ce8ab | < 0:3.15-3.module+el8.6.0+21745+f5f35196 | < 0:3.15-3.module+el8.6.0+21719+09b58c97 | < 0:3.18-4.module+el8.9.0+21697+6a5e98e7
- redhat•criu
< 0:3.15-3.module+el8.9.0+21673+408ce8ab | < 0:3.15-3.module+el8.6.0+21745+f5f35196 | < 0:3.15-3.module+el8.6.0+21719+09b58c97 | < 0:3.18-4.module+el8.9.0+21697+6a5e98e7
- redhat•criu-debuginfo
< 0:3.15-3.module+el8.9.0+21673+408ce8ab | < 0:3.15-3.module+el8.6.0+21745+f5f35196 | < 0:3.15-3.module+el8.6.0+21719+09b58c97 | < 0:3.18-4.module+el8.9.0+21697+6a5e98e7
- redhat•criu-debugsource
< 0:3.15-3.module+el8.9.0+21673+408ce8ab | < 0:3.15-3.module+el8.6.0+21745+f5f35196 | < 0:3.15-3.module+el8.6.0+21719+09b58c97 | < 0:3.18-4.module+el8.9.0+21697+6a5e98e7
- redhat•criu-devel
< 0:3.15-3.module+el8.9.0+21673+408ce8ab | < 0:3.15-3.module+el8.6.0+21745+f5f35196 | < 0:3.15-3.module+el8.6.0+21719+09b58c97 | < 0:3.18-4.module+el8.9.0+21697+6a5e98e7
- redhat•criu-libs
< 0:3.15-3.module+el8.9.0+21673+408ce8ab | < 0:3.15-3.module+el8.6.0+21745+f5f35196 | < 0:3.15-3.module+el8.6.0+21719+09b58c97 | < 0:3.18-4.module+el8.9.0+21697+6a5e98e7
- redhat•criu-libs-debuginfo
< 0:3.15-3.module+el8.9.0+21673+408ce8ab | < 0:3.15-3.module+el8.6.0+21745+f5f35196 | < 0:3.15-3.module+el8.6.0+21719+09b58c97 | < 0:3.18-4.module+el8.9.0+21697+6a5e98e7
- redhat•crun
< 0:1.8.7-1.module+el8.9.0+21673+408ce8ab | < 0:1.5-1.module+el8.6.0+21745+f5f35196 | < 0:1.4.4-1.module+el8.6.0+21719+09b58c97 | < 0:1.8.7-1.module+el8.9.0+21697+6a5e98e7
- redhat•crun-debuginfo
< 0:1.8.7-1.module+el8.9.0+21673+408ce8ab | < 0:1.5-1.module+el8.6.0+21745+f5f35196 | < 0:1.4.4-1.module+el8.6.0+21719+09b58c97 | < 0:1.8.7-1.module+el8.9.0+21697+6a5e98e7
- redhat•crun-debugsource
< 0:1.8.7-1.module+el8.9.0+21673+408ce8ab | < 0:1.5-1.module+el8.6.0+21745+f5f35196 | < 0:1.4.4-1.module+el8.6.0+21719+09b58c97 | < 0:1.8.7-1.module+el8.9.0+21697+6a5e98e7
- redhat•fuse-overlayfs
< 0:1.9-2.module+el8.9.0+21673+408ce8ab | < 0:1.9-1.module+el8.6.0+21745+f5f35196 | < 0:1.8.2-1.module+el8.6.0+21719+09b58c97 | < 0:1.12-1.module+el8.9.0+21697+6a5e98e7
- redhat•fuse-overlayfs-debuginfo
< 0:1.9-2.module+el8.9.0+21673+408ce8ab | < 0:1.9-1.module+el8.6.0+21745+f5f35196 | < 0:1.8.2-1.module+el8.6.0+21719+09b58c97 | < 0:1.12-1.module+el8.9.0+21697+6a5e98e7
- redhat•fuse-overlayfs-debugsource
< 0:1.9-2.module+el8.9.0+21673+408ce8ab | < 0:1.9-1.module+el8.6.0+21745+f5f35196 | < 0:1.8.2-1.module+el8.6.0+21719+09b58c97 | < 0:1.12-1.module+el8.9.0+21697+6a5e98e7
- redhat•libslirp
< 0:4.4.0-1.module+el8.9.0+21673+408ce8ab | < 0:4.4.0-1.module+el8.6.0+21745+f5f35196 | < 0:4.4.0-1.module+el8.6.0+21719+09b58c97 | < 0:4.4.0-1.module+el8.9.0+21697+6a5e98e7
- redhat•libslirp-debuginfo
< 0:4.4.0-1.module+el8.9.0+21673+408ce8ab | < 0:4.4.0-1.module+el8.6.0+21745+f5f35196 | < 0:4.4.0-1.module+el8.6.0+21719+09b58c97 | < 0:4.4.0-1.module+el8.9.0+21697+6a5e98e7
- redhat•libslirp-debugsource
< 0:4.4.0-1.module+el8.9.0+21673+408ce8ab | < 0:4.4.0-1.module+el8.6.0+21745+f5f35196 | < 0:4.4.0-1.module+el8.6.0+21719+09b58c97 | < 0:4.4.0-1.module+el8.9.0+21697+6a5e98e7
- redhat•libslirp-devel
< 0:4.4.0-1.module+el8.9.0+21673+408ce8ab | < 0:4.4.0-1.module+el8.6.0+21745+f5f35196 | < 0:4.4.0-1.module+el8.6.0+21719+09b58c97 | < 0:4.4.0-1.module+el8.9.0+21697+6a5e98e7
- redhat•netavark
< 2:1.0.1-38.module+el8.9.0+21673+408ce8ab | < 2:1.0.1-40.module+el8.6.0+21745+f5f35196 | < 2:1.0.1-29.module+el8.6.0+21719+09b58c97 | < 2:1.7.0-2.module+el8.9.0+21697+6a5e98e7
- redhat•oci-seccomp-bpf-hook
< 0:1.2.5-2.module+el8.9.0+21673+408ce8ab | < 0:1.2.6-1.module+el8.6.0+21745+f5f35196 | < 0:1.2.3-3.module+el8.6.0+21719+09b58c97 | < 0:1.2.9-1.module+el8.9.0+21697+6a5e98e7
- redhat•oci-seccomp-bpf-hook-debuginfo
< 0:1.2.5-2.module+el8.9.0+21673+408ce8ab | < 0:1.2.6-1.module+el8.6.0+21745+f5f35196 | < 0:1.2.3-3.module+el8.6.0+21719+09b58c97 | < 0:1.2.9-1.module+el8.9.0+21697+6a5e98e7
- redhat•oci-seccomp-bpf-hook-debugsource
< 0:1.2.5-2.module+el8.9.0+21673+408ce8ab | < 0:1.2.6-1.module+el8.6.0+21745+f5f35196 | < 0:1.2.3-3.module+el8.6.0+21719+09b58c97 | < 0:1.2.9-1.module+el8.9.0+21697+6a5e98e7
- redhat•podman
< 2:4.0.2-26.module+el8.9.0+21673+408ce8ab | < 2:4.2.0-3.el9_0 | < 2:4.2.0-3.module+el8.6.0+21745+f5f35196 | < 2:4.0.2-6.module+el8.6.0+21719+09b58c97 | < 3:4.6.1-9.module+el8.9.0+21697+6a5e98e7 | < 2:4.4.1-16.el9_2
- redhat•podman-catatonit
< 2:4.0.2-26.module+el8.9.0+21673+408ce8ab | < 2:4.2.0-3.el9_0 | < 2:4.2.0-3.module+el8.6.0+21745+f5f35196 | < 2:4.0.2-6.module+el8.6.0+21719+09b58c97 | < 3:4.6.1-9.module+el8.9.0+21697+6a5e98e7
- redhat•podman-catatonit-debuginfo
< 2:4.0.2-26.module+el8.9.0+21673+408ce8ab | < 2:4.2.0-3.el9_0 | < 2:4.2.0-3.module+el8.6.0+21745+f5f35196 | < 2:4.0.2-6.module+el8.6.0+21719+09b58c97 | < 3:4.6.1-9.module+el8.9.0+21697+6a5e98e7
- redhat•podman-debuginfo
< 2:4.0.2-26.module+el8.9.0+21673+408ce8ab | < 2:4.2.0-3.el9_0 | < 2:4.2.0-3.module+el8.6.0+21745+f5f35196 | < 2:4.0.2-6.module+el8.6.0+21719+09b58c97 | < 3:4.6.1-9.module+el8.9.0+21697+6a5e98e7 | < 2:4.4.1-16.el9_2
- redhat•podman-debugsource
< 2:4.0.2-26.module+el8.9.0+21673+408ce8ab | < 2:4.2.0-3.el9_0 | < 2:4.2.0-3.module+el8.6.0+21745+f5f35196 | < 2:4.0.2-6.module+el8.6.0+21719+09b58c97 | < 3:4.6.1-9.module+el8.9.0+21697+6a5e98e7 | < 2:4.4.1-16.el9_2
- redhat•podman-docker
< 2:4.0.2-26.module+el8.9.0+21673+408ce8ab | < 2:4.2.0-3.el9_0 | < 2:4.2.0-3.module+el8.6.0+21745+f5f35196 | < 2:4.0.2-6.module+el8.6.0+21719+09b58c97 | < 3:4.6.1-9.module+el8.9.0+21697+6a5e98e7 | < 2:4.4.1-16.el9_2
Showing first 50 affected entries in server-rendered view.
References (46)
- https://access.redhat.com/errata/RHSA-2024:2049
- https://access.redhat.com/errata/RHSA-2024:2055
- https://access.redhat.com/errata/RHSA-2024:2064
- https://access.redhat.com/errata/RHSA-2024:2066
- https://access.redhat.com/errata/RHSA-2024:2077
- https://access.redhat.com/errata/RHSA-2024:2084
- https://access.redhat.com/errata/RHSA-2024:2089
- https://access.redhat.com/errata/RHSA-2024:2090
- https://access.redhat.com/errata/RHSA-2024:2097
- https://access.redhat.com/errata/RHSA-2024:2098
- https://access.redhat.com/errata/RHSA-2024:2548
- https://access.redhat.com/errata/RHSA-2024:2645
- https://access.redhat.com/errata/RHSA-2024:2669
- https://access.redhat.com/errata/RHSA-2024:2672
- https://access.redhat.com/errata/RHSA-2024:2784
- https://access.redhat.com/errata/RHSA-2024:2877
- https://access.redhat.com/errata/RHSA-2024:3254
- https://access.redhat.com/security/cve/CVE-2024-1753
- https://bugzilla.redhat.com/show_bug.cgi?id=2265513
- https://github.com/containers/buildah/security/advisories/GHSA-pmf3-c36m-g5cf
- https://github.com/containers/podman/security/advisories/GHSA-874v-pj72-92f3
- https://pkg.go.dev/vuln/GO-2024-2658
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FCRZVUDOFM5CPREQKBEU2VK2QK62PSBP/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KOYMVMQ7RWMDTSKQTBO734BE3WQPI2AJ/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZVBSVZGVABPYIHK5HZM472NPGWMI7WXH/
- https://nvd.nist.gov/vuln/detail/CVE-2024-1753
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZVBSVZGVABPYIHK5HZM472NPGWMI7WXH
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KOYMVMQ7RWMDTSKQTBO734BE3WQPI2AJ
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FCRZVUDOFM5CPREQKBEU2VK2QK62PSBP
- https://github.com/containers/podman
- https://github.com/containers/buildah/commit/3deda19137f5dec0285bbb832bd93c22d860b087
- https://github.com/containers/buildah/commit/9de9c20ff368beb84b84fe660773d352519dc1c5
- https://github.com/containers/buildah/commit/a030f7b8cd373075affef1f86de43a87e502f3d8
- https://github.com/containers/buildah
- https://access.redhat.com/security/updates/classification/#important
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_2055.json
- https://www.cve.org/CVERecord?id=CVE-2024-1753
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_2064.json
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_2066.json
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_2084.json
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_2089.json
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_2090.json
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_2097.json
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_2098.json
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_2645.json
- https://security-tracker.debian.org/tracker/CVE-2024-1753