PT-2024-2232 · Podman+9 · Podman+9

Rmcnamara-Snyk

·

Published

2024-03-18

·

Updated

2025-08-28

·

CVE-2024-1753

CVSS v3.1

8.6

High

VectorAV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Buildah versions prior to the fixed version Podman versions prior to the fixed version
Description A flaw was found in Buildah and Podman, which allows containers to mount arbitrary locations on the host filesystem into build containers. A malicious Containerfile can use a dummy image with a symbolic link to the host filesystem as a mount source and cause the mount operation to mount the host filesystem during a build-time RUN step. The commands inside the RUN step will then have read-write access to the host filesystem, allowing for full container escape at build time. Users running containers with root privileges are impacted, allowing a container to run with read/write access to the host system files when selinux is not enabled. With selinux enabled, some read access is allowed.
Recommendations To resolve the issue, apply the patch to Buildah, which will then be vendored into Podman. Ensure selinux controls are in place to avoid compromising sensitive system files and systems. With "setenforce 0" set, the root file system is open for modification with this exploit. With "setenforce 1" set, files cannot be changed, but the contents of the / directory can be displayed. As a temporary workaround, consider disabling the build function in Podman and Buildah until a patch is available. Restrict access to the build command to minimize the risk of exploitation. Avoid using the --mount=type=bind option in the build command until the issue is resolved.

Fix

Link Following

Improper Privilege Management

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:2055
ALSA-2024:2084
ALSA-2024:2098
ALSA-2024:2548
ALSA-2024:3254
ALT-PU-2024-17358
ALT-PU-2024-4349
ALT-PU-2024-4351
ALT-PU-2024-4644
ALT-PU-2024-4646
ALT-PU-2024-7024
ALT-PU-2025-10794
AZL-36899
AZL-42506
AZL-42509
AZL-42546
AZL-42561
BDU:2024-02163
CESA-2024_2084
CESA-2024_2098
CESA-2024_3254
CVE-2024-1753
GHSA-874V-PJ72-92F3
GHSA-PMF3-C36M-G5CF
GO-2024-2658
INFSA-2024_2548
MGASA-2024-0343
OESA-2025-1059
OPENSUSE-SU-2024:13784-1
OPENSUSE-SU-2024:13826-1
OPENSUSE-SU-2024_1059-1
OPENSUSE-SU-2024_1143-1
OPENSUSE-SU-2024_1144-1
OPENSUSE-SU-2024_1145-1
OPENSUSE-SU-2024_1146-1
OPENSUSE-SU-2024_3120-1
OPENSUSE-SU-2024_3151-1
OPENSUSE-SU-2024_3186-1
OPENSUSE-SU-2025_0267-1
OPENSUSE-SU-2025_0775-1
RHSA-2024:2049
RHSA-2024:2055
RHSA-2024:2064
RHSA-2024:2066
RHSA-2024:2077
RHSA-2024:2084
RHSA-2024:2089
RHSA-2024:2090
RHSA-2024:2097
RHSA-2024:2098
RHSA-2024:2548
RHSA-2024:2645
RHSA-2024:2669
RHSA-2024:2672
RHSA-2024:2784
RHSA-2024:2877
RHSA-2024:3254
RHSA-2024_2055
RHSA-2024_2084
RHSA-2024_2098
RHSA-2024_2548
RHSA-2024_3254
RLSA-2024:2084
RLSA-2024:2098
RLSA-2024:2548
RLSA-2024:3254
SUSE-SU-2024:1058-1
SUSE-SU-2024:1059-1
SUSE-SU-2024:1142-1
SUSE-SU-2024:1143-1
SUSE-SU-2024:1144-1
SUSE-SU-2024:1145-1
SUSE-SU-2024:1146-1
SUSE-SU-2024:3120-1
SUSE-SU-2024:3151-1
SUSE-SU-2024:3186-1
SUSE-SU-2024_1058-1
SUSE-SU-2024_1059-1
SUSE-SU-2024_1142-1
SUSE-SU-2024_1143-1
SUSE-SU-2024_1144-1
SUSE-SU-2024_1145-1
SUSE-SU-2024_1146-1
SUSE-SU-2024_3151-1
SUSE-SU-2024_3186-1
SUSE-SU-2025:0267-1
SUSE-SU-2025:0775-1
SUSE-SU-2025:20013-1
SUSE-SU-2025:20279-1
SUSE-SU-2025_0267-1

Affected Products

Alt Linux
Almalinux
Buildah
Centos
Debian
Podman
Red Hat
Red Os
Rocky Linux
Suse