CVE Vulnerabilities

CVE-2024-11218

Improper Privilege Management

Published: Jan 22, 2025 | Modified: Mar 05, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
8.6 IMPORTANT
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Ubuntu
MEDIUM

A vulnerability was found in podman build and buildah. This issue occurs in a container breakout by using –jobs=2 and a race condition when building a malicious Containerfile. SELinux might mitigate it, but even with SELinux on, it still allows the enumeration of files and directories on the host.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Red Hat Enterprise Linux 8 RedHat container-tools:rhel8-8100020250124120243.afee755d *
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support RedHat container-tools:rhel8-8060020250203202123.3b538bd8 *
Red Hat Enterprise Linux 8.6 Telecommunications Update Service RedHat container-tools:rhel8-8060020250203202123.3b538bd8 *
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions RedHat container-tools:rhel8-8060020250203202123.3b538bd8 *
Red Hat Enterprise Linux 8.8 Extended Update Support RedHat container-tools:rhel8-8080020250207173112.0f77c1b7 *
Red Hat Enterprise Linux 9 RedHat podman-4:5.2.2-13.el9_5 *
Red Hat Enterprise Linux 9 RedHat buildah-2:1.37.6-1.el9_5 *
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions RedHat podman-2:4.2.0-6.el9_0 *
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions RedHat buildah-1:1.26.9-1.el9_0 *
Red Hat Enterprise Linux 9.2 Extended Update Support RedHat buildah-1:1.29.5-1.el9_2 *
Red Hat Enterprise Linux 9.2 Extended Update Support RedHat podman-2:4.4.1-22.el9_2 *
Red Hat Enterprise Linux 9.4 Extended Update Support RedHat buildah-2:1.33.12-2.el9_4 *
Red Hat Enterprise Linux 9.4 Extended Update Support RedHat podman-4:4.9.4-17.el9_4 *
Red Hat OpenShift Container Platform 4.14 RedHat podman-3:4.4.1-22.rhaos4.14.el9 *
Red Hat OpenShift Container Platform 4.15 RedHat podman-3:4.4.1-33.rhaos4.15.el9 *
Red Hat OpenShift Container Platform 4.16 RedHat podman-4:4.9.4-13.rhaos4.16.el8 *
Red Hat OpenShift Container Platform 4.16 RedHat buildah-2:1.33.12-1.rhaos4.16.el9 *
Red Hat OpenShift Container Platform 4.16 RedHat rhcos-416.94.202502180249-0 *
Red Hat OpenShift Container Platform 4.17 RedHat podman-5:5.2.2-2.rhaos4.17.el9 *
Red Hat OpenShift Container Platform 4.17 RedHat buildah-2:1.33.12-1.rhaos4.17.el9 *
Red Hat OpenShift Container Platform 4.18 RedHat buildah-2:1.33.12-1.rhaos4.18.el9 *

Potential Mitigations

References