PT-2025-1315 · Podman+9 · Podman+9

Published

2025-01-20

·

Updated

2025-09-19

·

CVE-2024-11218

CVSS v3.1

8.6

High

VectorAV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions podman versions prior to 5.3.2 buildah versions prior to 1.38.1
Description A vulnerability was found in podman build and buildah. This issue occurs in a container breakout by using --jobs=2 and a race condition when building a malicious Containerfile. SELinux might mitigate it, but even with SELinux on, it still allows the enumeration of files and directories on the host.
Recommendations podman versions prior to 5.3.2: Update to podman version 5.3.2 or later to resolve the issue. buildah versions prior to 1.38.1: Update to buildah version 1.38.1 or later to resolve the issue.

Fix

DoS

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025:0922
ALSA-2025:0923
ALSA-2025:1372
AZL-55942
AZL-55945
AZL-55953
AZL-55959
BDU:2025-01013
CESA-2025_1372
CVE-2024-11218
GHSA-5VPC-35F4-R8W6
GO-2025-3414
INFSA-2025_0922
INFSA-2025_0923
INFSA-2025_1372
OESA-2025-2297
OPENSUSE-SU-2025:14689-1
OPENSUSE-SU-2025:14710-1
OPENSUSE-SU-2025_0267-1
OPENSUSE-SU-2025_0297-1
OPENSUSE-SU-2025_0301-1
OPENSUSE-SU-2025_0319-1
OPENSUSE-SU-2025_0320-1
OPENSUSE-SU-2025_0382-1
OPENSUSE-SU-2025_0775-1
RHSA-2025:0830
RHSA-2025:0878
RHSA-2025:0922
RHSA-2025:0923
RHSA-2025:1186
RHSA-2025:1187
RHSA-2025:1188
RHSA-2025:1189
RHSA-2025:1207
RHSA-2025:1275
RHSA-2025:1295
RHSA-2025:1296
RHSA-2025:1372
RHSA-2025:1453
RHSA-2025:1713
RHSA-2025:1908
RHSA-2025:1910
RHSA-2025:1914
RHSA-2025:2443
RHSA-2025:2456
RHSA-2025:2703
RHSA-2025:2712
RHSA-2025_0922
RHSA-2025_0923
RHSA-2025_1372
RLSA-2025:0922
RLSA-2025:1372
SUSE-SU-2025:0267-1
SUSE-SU-2025:0297-1
SUSE-SU-2025:0301-1
SUSE-SU-2025:0319-1
SUSE-SU-2025:0320-1
SUSE-SU-2025:0382-1
SUSE-SU-2025:0775-1
SUSE-SU-2025:20143-1
SUSE-SU-2025:20279-1
SUSE-SU-2025_0267-1
SUSE-SU-2025_0301-1
SUSE-SU-2025_0319-1
SUSE-SU-2025_0320-1
SUSE-SU-2025_0382-1

Affected Products

Almalinux
Astra Linux
Centos
Debian
Red Hat
Red Os
Rocky Linux
Suse
Buildah
Podman