SB2024032833 - Multiple vulnerabilities in buildah
Published: March 28, 2024 Updated: April 23, 2024
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 3 secuirty vulnerabilities.
1) Improper Privilege Management (CVE-ID: CVE-2024-1753)
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to the affected application allows containers to mount arbitrary locations on the host filesystem into build containers. A remote attacker can escalate privileges.
2) Infinite loop (CVE-ID: CVE-2024-24786)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to infinite loop when parsing data in an invalid JSON format within the protojson.Unmarshal() function. A remote attacker can consume all available system resources and cause denial of service conditions.
3) Resource exhaustion (CVE-ID: CVE-2023-39325)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to excessive consumption of internal resources when handling HTTP/2 requests. A remote attacker can bypass the http2.Server.MaxConcurrentStreams setting by creating new connections while the current connections are still being processed, trigger resource exhaustion and perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://github.com/containers/buildah/releases/tag/v1.32.3"
- https://github.com/containers/buildah/releases/tag/v1.32.3</a></p><p><a
- https://github.com/containers/buildah/releases/tag/v1.29.3"
- https://github.com/containers/buildah/releases/tag/v1.29.3</a></p><p>
- https://github.com/containers/buildah/releases/tag/v1.27.4<br></p>
- https://github.com/containers/buildah/releases/tag/v1.32.3