Vulnerability CVE-2024-1753: Information

Description

A flaw was found in Buildah (and subsequently Podman Build) which allows containers to mount arbitrary locations on the host filesystem into build containers. A malicious Containerfile can use a dummy image with a symbolic link to the root filesystem as a mount source and cause the mount operation to mount the host root filesystem inside the RUN step. The commands inside the RUN step will then have read-write access to the host filesystem, allowing for full container escape at build time.

Published: March 18, 2024
Modified: May 17, 2024
Error type identifier: CWE-269

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
buildahsisyphus1.35.1-alt11.35.4-alt1ALT-PU-2024-4351-1343349Fixed
buildahsisyphus_riscv641.35.1-alt11.35.3-alt1ALT-PU-2024-4416-1-Fixed
buildahsisyphus_loongarch641.35.1-alt1.11.35.3-alt1ALT-PU-2024-4429-1-Fixed
buildahp101.34.3-alt0.p101.34.3-alt0.p10ALT-PU-2024-4646-2343760Fixed
buildahc10f11.34.3-alt0.p101.34.3-alt0.p10ALT-PU-2024-7024-3345716Fixed
podmansisyphus5.0.0-alt15.0.3-alt1ALT-PU-2024-4349-1343349Fixed
podmansisyphus_riscv645.0.0-alt15.0.2-alt1.1ALT-PU-2024-4415-1-Fixed
podmansisyphus_loongarch645.0.0-alt15.0.2-alt1.1ALT-PU-2024-4426-1-Fixed
podmanp104.9.4-alt0.p104.9.4-alt0.p10ALT-PU-2024-4644-2343760Fixed

References to Advisories, Solutions, and Tools