CVE-2024-9675

Aliases:GHSA-586p-749j-fhwpGO-2024-3186RHSA-2024:8563RHSA-2024:8675RHSA-2024:8679RHSA-2024:8703RHSA-2024:8707RHSA-2024:8708RHSA-2024:8709RHSA-2024:8994DEBIAN-CVE-2024-9675CGA-p5g4-cw2q-fhqqCGA-943p-wmqh-vv34CGA-pp94-7hvp-38mcCGA-rgpv-p65h-49j8
Modified
Published: 09 Oct 2024, 14:32
Last modified:07 Aug 2026, 13:25

Vulnerability Summary

Overall Risk (default)
medium
31/100
CVSS Score
7.8 HIGH
v3.1 (cve.org)
EPSS Score
0.39% LOW
0% probability +0.26%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

09 Oct 2024, 14:32
Published
Vulnerability first disclosed
07 Aug 2026, 13:25
Last Modified
Vulnerability information updated

Description

A vulnerability was found in Buildah. Cache mounts do not properly validate that user-specified paths for the cache are within our cache directory, allowing a `RUN` instruction in a Container file to mount an arbitrary directory from the host (read/write) into the container as long as those files can be accessed by the user running Buildah.

CVSS Metrics

  • v4.0MEDIUMScore: 5.3CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
  • v3.1HIGHScore: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • v3.1MEDIUMScore: 4.4CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

EPSS Trends

Current EPSS score: 0.39% Percentile: 33%

Techniques & Countermeasures

  • CWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

    The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Affected Systems

  • chainguardbuildah

    < 1.39.0-r2

  • chainguardprometheus-podman-exporter

    < 1.13.3-r2

  • wolfibuildah

    < 1.39.0-r2

  • buildah_projectbuildah

    na

  • debiangolang-github-containers-buildah

    all | all | < 1.37.4+ds1-1 | < 1.37.4+ds1-1

  • github.com/containersbuildah

    < 1.37.1 | < 1.38.0

  • redhatenterprise_linux

    8.0 | 9.0

  • redhatenterprise_linux_eus

    8.8 | 9.0 | 9.2 | 9.4

  • redhatenterprise_linux_for_arm_64

    8.0_aarch64 | 9.0_aarch64

  • redhatenterprise_linux_for_arm_64_eus

    8.8_aarch64 | 9.0_aarch64 | 9.2_aarch64 | 9.4_aarch64

  • redhatenterprise_linux_for_ibm_z_systems

    8.0_s390x | 9.0_s390x

  • redhatenterprise_linux_for_ibm_z_systems_eus

    8.8_s390x | 9.0_s390x | 9.2_s390x | 9.4_s390x

  • redhatenterprise_linux_for_power_little_endian

    8.0_ppc64le | 9.0_ppc64le

  • redhatenterprise_linux_for_power_little_endian_eus

    8.8_ppc64le | 9.0_ppc64le | 9.2_ppc64le | 9.4_ppc64le

  • redhatenterprise_linux_server_aus

    8.6 | 9.2 | 9.4

  • redhatenterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions

    8.6_ppc64le | 8.8_ppc64le | 9.0_ppc64le | 9.2_ppc64le | 9.4_ppc64le

  • redhatenterprise_linux_server_tus

    8.6 | 8.8

  • redhatenterprise_linux_update_services_for_sap_solutions

    8.6 | 8.8 | 9.0 | 9.2 | 9.4

  • redhatopenshift_container_platform

    4.13 | 4.14 | 4.15 | 4.16 | 4.17

  • redhataardvark-dns

    < 2:1.0.1-40.module+el8.6.0+22399+813f5137 | < 2:1.5.0-2.module+el8.8.0+22334+bb93e398

  • redhatbuildah

    < 2:1.33.10-1.el9_4 | < 1:1.26.8-2.el9_0 | < 1:1.26.8-1.module+el8.6.0+22399+813f5137 | < 1:1.29.4-1.module+el8.8.0+22398+6ad0f5ed | < 1:1.29.4-1.el9_2

  • redhatbuildah-debuginfo

    < 2:1.33.10-1.el9_4 | < 1:1.26.8-2.el9_0 | < 1:1.26.8-1.module+el8.6.0+22399+813f5137 | < 1:1.29.4-1.module+el8.8.0+22398+6ad0f5ed | < 1:1.29.4-1.el9_2

  • redhatbuildah-debugsource

    < 2:1.33.10-1.el9_4 | < 1:1.26.8-2.el9_0 | < 1:1.26.8-1.module+el8.6.0+22399+813f5137 | < 1:1.29.4-1.module+el8.8.0+22398+6ad0f5ed | < 1:1.29.4-1.el9_2

  • redhatbuildah-tests

    < 2:1.33.10-1.el9_4 | < 1:1.26.8-2.el9_0 | < 1:1.26.8-1.module+el8.6.0+22399+813f5137 | < 1:1.29.4-1.module+el8.8.0+22398+6ad0f5ed | < 1:1.29.4-1.el9_2

  • redhatbuildah-tests-debuginfo

    < 2:1.33.10-1.el9_4 | < 1:1.26.8-2.el9_0 | < 1:1.26.8-1.module+el8.6.0+22399+813f5137 | < 1:1.29.4-1.module+el8.8.0+22398+6ad0f5ed | < 1:1.29.4-1.el9_2

  • redhatcockpit-podman

    < 0:49.1-1.module+el8.6.0+22399+813f5137 | < 0:63.1-1.module+el8.8.0+22334+bb93e398

  • redhatconmon

    < 2:2.1.4-1.module+el8.6.0+22399+813f5137 | < 3:2.1.6-1.module+el8.8.0+22334+bb93e398

  • redhatconmon-debuginfo

    < 2:2.1.4-1.module+el8.6.0+22399+813f5137 | < 3:2.1.6-1.module+el8.8.0+22334+bb93e398

  • redhatconmon-debugsource

    < 2:2.1.4-1.module+el8.6.0+22399+813f5137 | < 3:2.1.6-1.module+el8.8.0+22334+bb93e398

  • redhatcontainer-selinux

    < 2:2.189.0-1.module+el8.6.0+22399+813f5137 | < 2:2.229.0-1.module+el8.8.0+22334+bb93e398

  • redhatcontainernetworking-plugins

    < 1:1.1.1-5.module+el8.6.0+22399+813f5137 | < 1:1.2.0-2.module+el8.8.0+22334+bb93e398

  • redhatcontainernetworking-plugins-debuginfo

    < 1:1.1.1-5.module+el8.6.0+22399+813f5137 | < 1:1.2.0-2.module+el8.8.0+22334+bb93e398

  • redhatcontainernetworking-plugins-debugsource

    < 1:1.1.1-5.module+el8.6.0+22399+813f5137 | < 1:1.2.0-2.module+el8.8.0+22334+bb93e398

  • redhatcontainers-common

    < 2:1-40.module+el8.6.0+22399+813f5137 | < 2:1-67.module+el8.8.0+22334+bb93e398

  • redhatcrit

    < 0:3.15-3.module+el8.6.0+22399+813f5137 | < 0:3.15-4.module+el8.8.0+22334+bb93e398

  • redhatcriu

    < 0:3.15-3.module+el8.6.0+22399+813f5137 | < 0:3.15-4.module+el8.8.0+22334+bb93e398

  • redhatcriu-debuginfo

    < 0:3.15-3.module+el8.6.0+22399+813f5137 | < 0:3.15-4.module+el8.8.0+22334+bb93e398

  • redhatcriu-debugsource

    < 0:3.15-3.module+el8.6.0+22399+813f5137 | < 0:3.15-4.module+el8.8.0+22334+bb93e398

  • redhatcriu-devel

    < 0:3.15-3.module+el8.6.0+22399+813f5137 | < 0:3.15-4.module+el8.8.0+22334+bb93e398

  • redhatcriu-libs

    < 0:3.15-3.module+el8.6.0+22399+813f5137 | < 0:3.15-4.module+el8.8.0+22334+bb93e398

  • redhatcriu-libs-debuginfo

    < 0:3.15-3.module+el8.6.0+22399+813f5137 | < 0:3.15-4.module+el8.8.0+22334+bb93e398

  • redhatcrun

    < 0:1.5-1.module+el8.6.0+22399+813f5137 | < 0:1.8.4-2.module+el8.8.0+22334+bb93e398

  • redhatcrun-debuginfo

    < 0:1.5-1.module+el8.6.0+22399+813f5137 | < 0:1.8.4-2.module+el8.8.0+22334+bb93e398

  • redhatcrun-debugsource

    < 0:1.5-1.module+el8.6.0+22399+813f5137 | < 0:1.8.4-2.module+el8.8.0+22334+bb93e398

  • redhatfuse-overlayfs

    < 0:1.9-1.module+el8.6.0+22399+813f5137 | < 0:1.11-1.module+el8.8.0+22334+bb93e398

  • redhatfuse-overlayfs-debuginfo

    < 0:1.9-1.module+el8.6.0+22399+813f5137 | < 0:1.11-1.module+el8.8.0+22334+bb93e398

  • redhatfuse-overlayfs-debugsource

    < 0:1.9-1.module+el8.6.0+22399+813f5137 | < 0:1.11-1.module+el8.8.0+22334+bb93e398

  • redhatlibslirp

    < 0:4.4.0-1.module+el8.6.0+22399+813f5137 | < 0:4.4.0-1.module+el8.8.0+22334+bb93e398

  • redhatlibslirp-debuginfo

    < 0:4.4.0-1.module+el8.6.0+22399+813f5137 | < 0:4.4.0-1.module+el8.8.0+22334+bb93e398

  • redhatlibslirp-debugsource

    < 0:4.4.0-1.module+el8.6.0+22399+813f5137 | < 0:4.4.0-1.module+el8.8.0+22334+bb93e398

Showing first 50 affected entries in server-rendered view.

References (45)