PT-2024-7820 · Buildah+9 · Buildah+9

Published

2024-10-09

·

Updated

2025-08-25

·

CVE-2024-9675

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Buildah (affected versions not specified)
Description A vulnerability exists in Buildah due to incorrect restriction of the path name to a directory with limited access. This issue allows an attacker to elevate privileges in the system by exploiting the fact that cache mounts do not properly validate user-specified paths for the cache, enabling a RUN instruction in a Container file to mount an arbitrary directory from the host into the container. The attacker can access files as long as they can be accessed by the user running Buildah.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:8563
ALSA-2024:8846
ALSA-2024:9051
ALSA-2024:9454
ALSA-2024:9459
ALT-PU-2024-16576
ALT-PU-2024-16578
BDU:2024-09320
CESA-2024_8846
CVE-2024-9675
GHSA-586P-749J-FHWP
GO-2024-3186
INFSA-2024_8563
INFSA-2024_8846
INFSA-2024_9051
INFSA-2024_9454
INFSA-2024_9459
OESA-2025-1053
OESA-2025-1055
OPENSUSE-SU-2024:0350-1
OPENSUSE-SU-2024:14405-1
OPENSUSE-SU-2024:14409-1
OPENSUSE-SU-2024:14447-1
OPENSUSE-SU-2024_3728-1
OPENSUSE-SU-2024_3741-1
OPENSUSE-SU-2024_3911-1
OPENSUSE-SU-2024_3988-1
OPENSUSE-SU-2024_4303-1
OPENSUSE-SU-2025_0267-1
OPENSUSE-SU-2025_0775-1
RHSA-2024:8563
RHSA-2024:8675
RHSA-2024:8679
RHSA-2024:8686
RHSA-2024:8690
RHSA-2024:8700
RHSA-2024:8703
RHSA-2024:8707
RHSA-2024:8708
RHSA-2024:8709
RHSA-2024:8846
RHSA-2024:8984
RHSA-2024:8994
RHSA-2024:9051
RHSA-2024:9454
RHSA-2024:9459
RHSA-2024_8563
RHSA-2024_8846
RHSA-2024_9051
RHSA-2024_9454
RHSA-2024_9459
RLSA-2024:8563
RLSA-2024:8846
RLSA-2024:9051
SUSE-SU-2024:3728-1
SUSE-SU-2024:3741-1
SUSE-SU-2024:3911-1
SUSE-SU-2024:3988-1
SUSE-SU-2024:4303-1
SUSE-SU-2024_3728-1
SUSE-SU-2025:0267-1
SUSE-SU-2025:0775-1
SUSE-SU-2025:20080-1
SUSE-SU-2025_0267-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Buildah
Centos
Debian
Red Hat
Red Os
Rocky Linux
Suse