Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2024-11218

Published: January 23, 2025Last modified: January 24, 2025

Description

A vulnerability was found in `podman build` and `buildah.` This issue occurs in a container breakout by using --jobs=2 and a race condition when building a malicious Containerfile. SELinux might mitigate it, but even with SELinux on, it still allows the enumeration of files and directories on the host.

Severity score breakdown

ParameterValue
Base score8.6
Attack VectorLOCAL
Attack complexityLOW
Privileges requiredNONE
User interactionREQUIRED
ScopeCHANGED
ConfidentialityHIGH
Integrity impactHIGH
Availability impactHIGH
VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSbuildahFixed (1.37.6-r0)
podmanFixed (5.2.5-r1)
StreambuildahFixed (1.38.1-r0)
podmanFixed (5.3.2-r0)

References

ON THIS PAGE