cbcvebase.
CVE-2024-9676
published 2024-10-15

CVE-2024-9676: A vulnerability was found in Podman, Buildah, and CRI-O. A symlink traversal vulnerability in the containers/storage library can cause Podman, Buildah, and…

medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
A vulnerability was found in Podman, Buildah, and CRI-O. A symlink traversal vulnerability in the containers/storage library can cause Podman, Buildah, and CRI-O to hang and result in a denial of service via OOM kill when running a malicious image using an automatically assigned user namespace (`--userns=auto` in Podman and Buildah). The containers/storage library will read /etc/passwd inside the container, but does not properly validate if that file is a symlink, which can be used to cause the library to read an arbitrary file on the host.

Affected

46 ranges· showing 25
VendorProductVersion rangeFixed in
debiangolang-github-containers-storage< golang-github-containers-storage 1.55.1+ds1-1 (forky)golang-github-containers-storage 1.55.1+ds1-1 (forky)
msrcazl3_libcontainers-common_20240213-3_on_azure_linux_3.0
msrcazl3_skopeo_1.14.4-3_on_azure_linux_3.0
msrcazl3_skopeo_1.14.4-5_on_azure_linux_3.0
msrccbl2_cri-o_1.22.3-14_on_cbl_mariner_2.0
msrccbl2_libcontainers-common_20210626-7_on_cbl_mariner_2.0
msrccbl2_skopeo_1.14.2-10_on_cbl_mariner_2.0
msrccbl2_skopeo_1.14.2-9_on_cbl_mariner_2.0
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
redhatenterprise_linux
redhatenterprise_linux_eus
redhatenterprise_linux_for_arm_64
redhatenterprise_linux_for_arm_64_eus
redhatenterprise_linux_for_ibm_z_systems
redhatenterprise_linux_for_ibm_z_systems_eus
redhatenterprise_linux_for_power_little_endian
redhatenterprise_linux_for_power_little_endian_eus
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_for_power_little_endian_update_services_for_sap_solution
redhatopenshift_container_platform
redhatopenshift_container_platform
redhatopenshift_container_platform
redhatopenshift_container_platform
redhatopenshift_container_platform

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv6.5MEDIUM