PT-2024-7952 · Docker+9 · Docker+11

Published

2024-10-01

·

Updated

2026-02-21

·

CVE-2024-9407

CVSS v4.0

5.9

Medium

VectorAV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Docker (affected versions not specified) Podman (affected versions not specified) Buildah (affected versions not specified)
Description A vulnerability exists in the bind-propagation option of the Dockerfile RUN --mount instruction, where the system does not properly validate the input passed to this option. This allows users to pass arbitrary parameters to the mount instruction, potentially mounting sensitive directories from the host into a container during the build process and modifying the contents of those mounted files. The issue can bypass SELinux protection by relabeling the source directory to give the container access to host files.
Recommendations For Docker, consider disabling the bind-propagation option in the Dockerfile RUN --mount instruction until a patch is available. For Podman, restrict access to the --mount instruction to minimize the risk of exploitation. For Buildah, avoid using the --mount option with arbitrary parameters until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:8846
ALSA-2024:9051
ALSA-2024:9454
ALSA-2024:9459
ALT-PU-2024-16576
ALT-PU-2024-16578
AZL-50262
AZL-50268
BDU:2024-09460
CESA-2024_8846
CVE-2024-9407
GHSA-FHQQ-8F65-5XFC
GO-2024-3169
INFSA-2024_8846
INFSA-2024_9051
INFSA-2024_9454
INFSA-2024_9459
MGASA-2024-0343
OESA-2025-1053
OESA-2025-1055
OESA-2025-2257
OESA-2025-2258
OESA-2025-2259
OESA-2025-2297
OPENSUSE-SU-2024:0350-1
OPENSUSE-SU-2024:14388-1
OPENSUSE-SU-2024:14390-1
OPENSUSE-SU-2024:14447-1
OPENSUSE-SU-2024_3545-1
OPENSUSE-SU-2024_3741-1
OPENSUSE-SU-2024_3911-1
OPENSUSE-SU-2024_3988-1
OPENSUSE-SU-2024_4303-1
OPENSUSE-SU-2025_0267-1
OPENSUSE-SU-2025_0319-1
OPENSUSE-SU-2025_0320-1
OPENSUSE-SU-2025_0775-1
RHSA-2024:8846
RHSA-2024:9051
RHSA-2024:9454
RHSA-2024:9459
RHSA-2024:9926
RHSA-2024_8846
RHSA-2024_9051
RHSA-2024_9454
RHSA-2024_9459
RLSA-2024:8846
RLSA-2024:9051
SUSE-SU-2024:3545-1
SUSE-SU-2024:3741-1
SUSE-SU-2024:3911-1
SUSE-SU-2024:3988-1
SUSE-SU-2024:4303-1
SUSE-SU-2024_3741-1
SUSE-SU-2025:0267-1
SUSE-SU-2025:0319-1
SUSE-SU-2025:0320-1
SUSE-SU-2025:0775-1
SUSE-SU-2025:20080-1
SUSE-SU-2025:20143-1
SUSE-SU-2025:20279-1
SUSE-SU-2025_0267-1
SUSE-SU-2025_0319-1
SUSE-SU-2025_0320-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Buildah
Centos
Debian
Docker
Podman
Red Hat
Red Os
Rocky Linux
Suse