CVE-2024-11218
published 2025-01-22CVE-2024-11218: A vulnerability was found in `podman build` and `buildah.` This issue occurs in a container breakout by using --jobs=2 and a race condition when building a…
PriorityP344high8.6CVSS 3.1
AVLACLPRNUIRSCCHIHAH
EPSS
0.36%
28.0th percentile
A vulnerability was found in `podman build` and `buildah.` This issue occurs in a container breakout by using --jobs=2 and a race condition when building a malicious Containerfile. SELinux might mitigate it, but even with SELinux on, it still allows the enumeration of files and directories on the host.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | golang-github-containers-buildah | < golang-github-containers-buildah 1.38.1+ds1-1 (forky) | golang-github-containers-buildah 1.38.1+ds1-1 (forky) |
| github.com | containers_buildah | >= 0 < 1.33.12 | 1.33.12 |
| github.com | containers_buildah | >= 1.35.0 < 1.35.5 | 1.35.5 |
| github.com | containers_buildah | >= 1.37.0 < 1.37.6 | 1.37.6 |
| github.com | containers_buildah | >= 1.38.0 < 1.38.1 | 1.38.1 |
CVSS provenance
nvdv3.18.6HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
osv8.6HIGH
vendor_debian8.6HIGH
vendor_redhat8.6HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
podman: buildah: Container breakout by using --jobs=2 and a race condition when building a malicious Containerfile
vendor_redhat·2025-01-20·CVSS 8.6
CVE-2024-11218 [HIGH] CWE-269 podman: buildah: Container breakout by using --jobs=2 and a race condition when building a malicious Containerfile
podman: buildah: Container breakout by using --jobs=2 and a race condition when building a malicious Containerfile
A vulnerability was found in `podman build` and `buildah.` This issue occurs in a container breakout by using --jobs=2 and a race condition when building a malicious Containerfile. SELinux might mitigate it, but even with SELinux on, it still allows the enumeration of files and directories on the host.
A vulnerability was found in `podman build` and `buildah.` This issue occurs in a container breakout by using --jobs=2 and a race condition when building a malicious Containerfile. SELinux might mitigate it, but even with SELinux on, it still allows the enumeration of files and directories on the host.
Statement: This vulnerability marked as important severity rather than mod
Debian
CVE-2024-11218: golang-github-containers-buildah - A vulnerability was found in `podman build` and `buildah.` This issue occurs in ...
vendor_debian·2024·CVSS 8.6
CVE-2024-11218 [HIGH] CVE-2024-11218: golang-github-containers-buildah - A vulnerability was found in `podman build` and `buildah.` This issue occurs in ...
A vulnerability was found in `podman build` and `buildah.` This issue occurs in a container breakout by using --jobs=2 and a race condition when building a malicious Containerfile. SELinux might mitigate it, but even with SELinux on, it still allows the enumeration of files and directories on the host.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1.38.1+ds1-1)
sid: resolved (fixed in 1.38.1+ds1-1)
trixie: resolved (fixed in 1.38.1+ds1-1)
OSV
Buildah allows build breakout using malicious Containerfiles and concurrent builds in github.com/containers/buildah
osv·2025-01-28
CVE-2024-11218 Buildah allows build breakout using malicious Containerfiles and concurrent builds in github.com/containers/buildah
Buildah allows build breakout using malicious Containerfiles and concurrent builds in github.com/containers/buildah
Buildah allows build breakout using malicious Containerfiles and concurrent builds in github.com/containers/buildah
OSV
CVE-2024-11218: A vulnerability was found in `podman build` and `buildah
osv·2025-01-22·CVSS 8.6
CVE-2024-11218 [HIGH] CVE-2024-11218: A vulnerability was found in `podman build` and `buildah
A vulnerability was found in `podman build` and `buildah.` This issue occurs in a container breakout by using --jobs=2 and a race condition when building a malicious Containerfile. SELinux might mitigate it, but even with SELinux on, it still allows the enumeration of files and directories on the host.
GHSA
Buildah allows build breakout using malicious Containerfiles and concurrent builds
ghsa·2025-01-21
CVE-2024-11218 [HIGH] CWE-269 Buildah allows build breakout using malicious Containerfiles and concurrent builds
Buildah allows build breakout using malicious Containerfiles and concurrent builds
### Impact
With careful use of the `--mount` flag in RUN instructions in Containerfiles, and by using either multi-stage builds with use of concurrently-executing build stages (e.g., using the `--jobs` CLI flag) or multiple separate but concurrently-executing builds, a malicious Containerfile can be used to expose content from the build host to the command being run using the RUN instruction. This can be used to read or write contents using the privileges of the process which is performing the build. When that process is a root-owned podman system service which is provided for use by unprivileged users, this includes the ability to read and write contents which the client should not be allowed to read and w
OSV
Buildah allows build breakout using malicious Containerfiles and concurrent builds
osv·2025-01-21
CVE-2024-11218 [HIGH] Buildah allows build breakout using malicious Containerfiles and concurrent builds
Buildah allows build breakout using malicious Containerfiles and concurrent builds
### Impact
With careful use of the `--mount` flag in RUN instructions in Containerfiles, and by using either multi-stage builds with use of concurrently-executing build stages (e.g., using the `--jobs` CLI flag) or multiple separate but concurrently-executing builds, a malicious Containerfile can be used to expose content from the build host to the command being run using the RUN instruction. This can be used to read or write contents using the privileges of the process which is performing the build. When that process is a root-owned podman system service which is provided for use by unprivileged users, this includes the ability to read and write contents which the client should not be allowed to read and w
No detection rules found.
No public exploits indexed.
https://access.redhat.com/errata/RHSA-2025:0830https://access.redhat.com/errata/RHSA-2025:0878https://access.redhat.com/errata/RHSA-2025:0922https://access.redhat.com/errata/RHSA-2025:0923https://access.redhat.com/errata/RHSA-2025:1186https://access.redhat.com/errata/RHSA-2025:1187https://access.redhat.com/errata/RHSA-2025:1188https://access.redhat.com/errata/RHSA-2025:1189https://access.redhat.com/errata/RHSA-2025:1207https://access.redhat.com/errata/RHSA-2025:1275https://access.redhat.com/errata/RHSA-2025:1295https://access.redhat.com/errata/RHSA-2025:1296https://access.redhat.com/errata/RHSA-2025:1372https://access.redhat.com/errata/RHSA-2025:1453https://access.redhat.com/errata/RHSA-2025:1707https://access.redhat.com/errata/RHSA-2025:1713https://access.redhat.com/errata/RHSA-2025:1908https://access.redhat.com/errata/RHSA-2025:1910https://access.redhat.com/errata/RHSA-2025:1914https://access.redhat.com/errata/RHSA-2025:2441https://access.redhat.com/errata/RHSA-2025:2443https://access.redhat.com/errata/RHSA-2025:2454https://access.redhat.com/errata/RHSA-2025:2456https://access.redhat.com/errata/RHSA-2025:2701https://access.redhat.com/errata/RHSA-2025:2703https://access.redhat.com/errata/RHSA-2025:2710https://access.redhat.com/errata/RHSA-2025:2712https://access.redhat.com/errata/RHSA-2025:3577https://access.redhat.com/errata/RHSA-2025:3798https://access.redhat.com/security/cve/CVE-2024-11218https://bugzilla.redhat.com/show_bug.cgi?id=2326231https://github.com/containers/buildah/pull/5918
2025-01-22
Published