PT-2024-7953 · Unknown+9 · Containers/Common+9

Paul Holzinger

·

Published

2024-10-01

·

Updated

2025-09-19

·

CVE-2024-9341

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions containers/common versions (affected versions not specified)
Description The issue is related to a flaw in the containers/common Go library, which incorrectly handles certain file paths when FIPS mode is enabled on a system. This allows an attacker to exploit symbolic links, tricking the system into mounting sensitive host directories inside a container and accessing critical host files, thus bypassing the intended isolation between containers and the host system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:8039
ALSA-2024:8112
ALSA-2024:8846
ALSA-2024:9454
ALSA-2024:9459
ALT-PU-2024-16576
ALT-PU-2024-16578
AZL-50058
AZL-50070
AZL-50091
AZL-50103
BDU:2024-09461
CESA-2024_8846
CVE-2024-9341
GHSA-MC76-5925-C5P6
GO-2024-3171
INFSA-2024_8039
INFSA-2024_8112
INFSA-2024_8846
INFSA-2024_9454
INFSA-2024_9459
MGASA-2024-0343
OESA-2025-1053
OESA-2025-1055
OESA-2025-2257
OESA-2025-2258
OESA-2025-2259
OESA-2025-2297
OPENSUSE-SU-2024:0350-1
OPENSUSE-SU-2024:14388-1
OPENSUSE-SU-2024:14390-1
OPENSUSE-SU-2024:14447-1
OPENSUSE-SU-2024_3545-1
OPENSUSE-SU-2024_3546-1
OPENSUSE-SU-2024_3911-1
OPENSUSE-SU-2024_3988-1
OPENSUSE-SU-2024_4303-1
OPENSUSE-SU-2025_0267-1
OPENSUSE-SU-2025_0775-1
RHSA-2024:7925
RHSA-2024:8039
RHSA-2024:8112
RHSA-2024:8238
RHSA-2024:8263
RHSA-2024:8428
RHSA-2024:8690
RHSA-2024:8694
RHSA-2024:8846
RHSA-2024:9454
RHSA-2024:9459
RHSA-2024_8039
RHSA-2024_8112
RHSA-2024_8846
RHSA-2024_9454
RHSA-2024_9459
RLSA-2024:8039
RLSA-2024:8846
SUSE-SU-2024:3545-1
SUSE-SU-2024:3546-1
SUSE-SU-2024:3911-1
SUSE-SU-2024:3988-1
SUSE-SU-2024:4303-1
SUSE-SU-2024_3545-1
SUSE-SU-2024_3988-1
SUSE-SU-2024_4303-1
SUSE-SU-2025:0267-1
SUSE-SU-2025:0775-1
SUSE-SU-2025:20080-1
SUSE-SU-2025_0267-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Debian
Red Hat
Red Os
Rocky Linux
Suse
Containers/Common