CVE-2024-9407
published 2024-10-01CVE-2024-9407: A vulnerability exists in the bind-propagation option of the Dockerfile RUN --mount instruction. The system does not properly validate the input passed to this…
PriorityP426medium4.7CVSS 3.1
AVLACHPRHUINSUCHILAN
EPSS
0.29%
20.9th percentile
A vulnerability exists in the bind-propagation option of the Dockerfile RUN --mount instruction. The system does not properly validate the input passed to this option, allowing users to pass arbitrary parameters to the mount instruction. This issue can be exploited to mount sensitive directories from the host into a container during the build process and, in some cases, modify the contents of those mounted files. Even if SELinux is used, this vulnerability can bypass its protection by allowing the source directory to be relabeled to give the container access to host files.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | golang-github-containers-buildah | < golang-github-containers-buildah 1.37.4+ds1-1 (forky) | golang-github-containers-buildah 1.37.4+ds1-1 (forky) |
| github.com | containers_buildah | >= 0 < 1.37.4 | 1.37.4 |
| github.com | containers_podman | >= 0 < 5.2.4 | 5.2.4 |
| github.com | containers_podman_v2 | >= 0 < 5.2.4 | 5.2.4 |
| github.com | containers_podman_v3 | >= 0 < 5.2.4 | 5.2.4 |
| github.com | containers_podman_v4 | >= 0 < 5.2.4 | 5.2.4 |
| github.com | containers_podman_v5 | >= 0 < 5.2.4 | 5.2.4 |
| msrc | azl3_libcontainers-common_20240213-3_on_azure_linux_3.0 | — | — |
CVSS provenance
nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:L/A:N
osv4.7MEDIUM
vendor_debian4.7MEDIUM
vendor_msrc4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Improper Input Validation in Buildah and Podman in github.com/containers/buildah
osv·2024-10-09
CVE-2024-9407 Improper Input Validation in Buildah and Podman in github.com/containers/buildah
Improper Input Validation in Buildah and Podman in github.com/containers/buildah
Improper Input Validation in Buildah and Podman in github.com/containers/buildah
GHSA
Improper Input Validation in Buildah and Podman
ghsa·2024-10-01
CVE-2024-9407 [MEDIUM] CWE-20 Improper Input Validation in Buildah and Podman
Improper Input Validation in Buildah and Podman
A vulnerability exists in the bind-propagation option of the Dockerfile RUN --mount instruction. The system does not properly validate the input passed to this option, allowing users to pass arbitrary parameters to the mount instruction. This issue can be exploited to mount sensitive directories from the host into a container during the build process and, in some cases, modify the contents of those mounted files. Even if SELinux is used, this vulnerability can bypass its protection by allowing the source directory to be relabeled to give the container access to host files.
OSV
CVE-2024-9407: A vulnerability exists in the bind-propagation option of the Dockerfile RUN --mount instruction
osv·2024-10-01·CVSS 4.7
CVE-2024-9407 [MEDIUM] CVE-2024-9407: A vulnerability exists in the bind-propagation option of the Dockerfile RUN --mount instruction
A vulnerability exists in the bind-propagation option of the Dockerfile RUN --mount instruction. The system does not properly validate the input passed to this option, allowing users to pass arbitrary parameters to the mount instruction. This issue can be exploited to mount sensitive directories from the host into a container during the build process and, in some cases, modify the contents of those mounted files. Even if SELinux is used, this vulnerability can bypass its protection by allowing the source directory to be relabeled to give the container access to host files.
OSV
Improper Input Validation in Buildah and Podman
osv·2024-10-01
CVE-2024-9407 [MEDIUM] Improper Input Validation in Buildah and Podman
Improper Input Validation in Buildah and Podman
A vulnerability exists in the bind-propagation option of the Dockerfile RUN --mount instruction. The system does not properly validate the input passed to this option, allowing users to pass arbitrary parameters to the mount instruction. This issue can be exploited to mount sensitive directories from the host into a container during the build process and, in some cases, modify the contents of those mounted files. Even if SELinux is used, this vulnerability can bypass its protection by allowing the source directory to be relabeled to give the container access to host files.
Microsoft
Buildah: podman: improper input validation in bind-propagation option of dockerfile run --mount instruction
vendor_msrc·2024-10-08·CVSS 4.7
CVE-2024-9407 [MEDIUM] CWE-20 Buildah: podman: improper input validation in bind-propagation option of dockerfile run --mount instruction
Buildah: podman: improper input validation in bind-propagation option of dockerfile run --mount instruction
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Red Hat
Buildah: Podman: Improper Input Validation in bind-propagation Option of Dockerfile RUN --mount Instruction
vendor_redhat·2024-10-01·CVSS 4.7
CVE-2024-9407 [MEDIUM] CWE-20 Buildah: Podman: Improper Input Validation in bind-propagation Option of Dockerfile RUN --mount Instruction
Buildah: Podman: Improper Input Validation in bind-propagation Option of Dockerfile RUN --mount Instruction
A vulnerability exists in the bind-propagation option of the Dockerfile RUN --mount instruction. The system does not properly validate the input passed to this option, allowing users to pass arbitrary parameters to the mount instruction. This issue can be exploited to mount sensitive directories from the host into a container during the build process and, in some cases, modify the contents of those mounted files. Even if SELinux is used, this vulnerability can bypass its protection by allowing the source directory to be relabeled to give the container access to host files.
A vulnerability exists in the bind-propagation option of the Dockerfile RUN --mount instruction. The system do
Debian
CVE-2024-9407: golang-github-containers-buildah - A vulnerability exists in the bind-propagation option of the Dockerfile RUN --mo...
vendor_debian·2024·CVSS 4.7
CVE-2024-9407 [MEDIUM] CVE-2024-9407: golang-github-containers-buildah - A vulnerability exists in the bind-propagation option of the Dockerfile RUN --mo...
A vulnerability exists in the bind-propagation option of the Dockerfile RUN --mount instruction. The system does not properly validate the input passed to this option, allowing users to pass arbitrary parameters to the mount instruction. This issue can be exploited to mount sensitive directories from the host into a container during the build process and, in some cases, modify the contents of those mounted files. Even if SELinux is used, this vulnerability can bypass its protection by allowing the source directory to be relabeled to give the container access to host files.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1.37.4+ds1-1)
sid: resolved (fixed in 1.37.4+ds1-1)
trixie: resolved (fixed in 1.37.4+ds1-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/errata/RHSA-2024:10147https://access.redhat.com/errata/RHSA-2024:8846https://access.redhat.com/errata/RHSA-2024:9051https://access.redhat.com/errata/RHSA-2024:9454https://access.redhat.com/errata/RHSA-2024:9459https://access.redhat.com/errata/RHSA-2024:9926https://access.redhat.com/security/cve/CVE-2024-9407https://bugzilla.redhat.com/show_bug.cgi?id=2315887https://github.com/advisories/GHSA-fhqq-8f65-5xfchttps://security.netapp.com/advisory/ntap-20241220-0010/
2024-10-01
Published