CVE Vulnerabilities

CVE-2024-11218

Improper Privilege Management

Published: Jan 22, 2025 | Modified: Oct 02, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
8.6 IMPORTANT
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

A vulnerability was found in podman build and buildah. This issue occurs in a container breakout by using –jobs=2 and a race condition when building a malicious Containerfile. SELinux might mitigate it, but even with SELinux on, it still allows the enumeration of files and directories on the host.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

NameVendorStart VersionEnd Version
Red Hat Enterprise Linux 8RedHatcontainer-tools:rhel8-8100020250124120243.afee755d*
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportRedHatcontainer-tools:rhel8-8060020250203202123.3b538bd8*
Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceRedHatcontainer-tools:rhel8-8060020250203202123.3b538bd8*
Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsRedHatcontainer-tools:rhel8-8060020250203202123.3b538bd8*
Red Hat Enterprise Linux 8.8 Extended Update SupportRedHatcontainer-tools:rhel8-8080020250207173112.0f77c1b7*
Red Hat Enterprise Linux 9RedHatpodman-4:5.2.2-13.el9_5*
Red Hat Enterprise Linux 9RedHatbuildah-2:1.37.6-1.el9_5*
Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsRedHatpodman-2:4.2.0-6.el9_0*
Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsRedHatbuildah-1:1.26.9-1.el9_0*
Red Hat Enterprise Linux 9.2 Extended Update SupportRedHatbuildah-1:1.29.5-1.el9_2*
Red Hat Enterprise Linux 9.2 Extended Update SupportRedHatpodman-2:4.4.1-22.el9_2*
Red Hat Enterprise Linux 9.4 Extended Update SupportRedHatbuildah-2:1.33.12-2.el9_4*
Red Hat Enterprise Linux 9.4 Extended Update SupportRedHatpodman-4:4.9.4-17.el9_4*
Red Hat OpenShift Container Platform 4.12RedHatrhcos-412.86.202503052321-0*
Red Hat OpenShift Container Platform 4.12RedHatpodman-3:4.2.0-13.rhaos4.12.el9*
Red Hat OpenShift Container Platform 4.13RedHatbuildah-1:1.29.5-1.rhaos4.13.el8*
Red Hat OpenShift Container Platform 4.13RedHatpodman-3:4.4.1-16.rhaos4.13.el8*
Red Hat OpenShift Container Platform 4.13RedHatrhcos-413.92.202503112237-0*
Red Hat OpenShift Container Platform 4.14RedHatpodman-3:4.4.1-22.rhaos4.14.el8*
Red Hat OpenShift Container Platform 4.14RedHatbuildah-1:1.29.5-1.rhaos4.14.el8*
Red Hat OpenShift Container Platform 4.14RedHatrhcos-414.92.202503100617-0*
Red Hat OpenShift Container Platform 4.15RedHatpodman-3:4.4.1-33.rhaos4.15.el8*
Red Hat OpenShift Container Platform 4.15RedHatbuildah-1:1.29.5-1.rhaos4.15.el8*
Red Hat OpenShift Container Platform 4.15RedHatrhcos-415.92.202503060749-0*
Red Hat OpenShift Container Platform 4.16RedHatpodman-4:4.9.4-13.rhaos4.16.el8*
Red Hat OpenShift Container Platform 4.16RedHatbuildah-2:1.33.12-1.rhaos4.16.el8*
Red Hat OpenShift Container Platform 4.16RedHatrhcos-416.94.202502180249-0*
Red Hat OpenShift Container Platform 4.17RedHatpodman-5:5.2.2-2.rhaos4.17.el8*
Red Hat OpenShift Container Platform 4.17RedHatbuildah-2:1.33.12-1.rhaos4.17.el8*
Red Hat OpenShift Container Platform 4.17RedHatrhcos-417.94.202504080421-0*
Red Hat OpenShift Container Platform 4.18RedHatbuildah-2:1.33.12-1.rhaos4.18.el9*
Red Hat OpenShift Container Platform 4.18RedHatrhcos-418.94.202504021150-0*
PodmanUbuntuplucky*

Potential Mitigations

References