Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-11218

Опубликовано: 22 янв. 2025
Источник: debian
EPSS Низкий

Описание

A vulnerability was found in `podman build` and `buildah.` This issue occurs in a container breakout by using --jobs=2 and a race condition when building a malicious Containerfile. SELinux might mitigate it, but even with SELinux on, it still allows the enumeration of files and directories on the host.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
golang-github-containers-buildahfixed1.38.1+ds1-1package
golang-github-containers-buildahno-dsabookwormpackage
golang-github-containers-buildahno-dsabullseyepackage

Примечания

  • https://github.com/advisories/GHSA-5vpc-35f4-r8w6

EPSS

Процентиль: 4%
0.00022
Низкий

Связанные уязвимости

CVSS3: 8.6
ubuntu
5 месяцев назад

A vulnerability was found in `podman build` and `buildah.` This issue occurs in a container breakout by using --jobs=2 and a race condition when building a malicious Containerfile. SELinux might mitigate it, but even with SELinux on, it still allows the enumeration of files and directories on the host.

CVSS3: 8.6
redhat
5 месяцев назад

A vulnerability was found in `podman build` and `buildah.` This issue occurs in a container breakout by using --jobs=2 and a race condition when building a malicious Containerfile. SELinux might mitigate it, but even with SELinux on, it still allows the enumeration of files and directories on the host.

CVSS3: 8.6
nvd
5 месяцев назад

A vulnerability was found in `podman build` and `buildah.` This issue occurs in a container breakout by using --jobs=2 and a race condition when building a malicious Containerfile. SELinux might mitigate it, but even with SELinux on, it still allows the enumeration of files and directories on the host.

suse-cvrf
4 месяца назад

Security update for podman

suse-cvrf
5 месяцев назад

Security update for buildah

EPSS

Процентиль: 4%
0.00022
Низкий