Permissions, Privileges, and Access Controls in buildah - CVE-2024-11218
Published: February 3, 2025 / Updated: April 28, 2025
Vulnerability details
The vulnerability allows a remote user to escalate privileges on the system.
The vulnerability exists due to improperly imposed security restrictions during the build process. A remote user can leverage usage of a --mount flag in RUN instructions in Containerfiles along with multi-stage builds with use of concurrently-executing build stages or multiple separate but concurrently-executing builds to expose content from the build host and perform read/write operations on the system with privileges of the podman system service.
Affected software
Red Hat OpenShift Container Platform
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
SUSE Enterprise Storage
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Containers Module
openSUSE Leap
openEuler
Fedora
IBM Qradar SIEM
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
toolbox
toolbox-tests
udica
containers-common
runc
slirp4netns
oci-seccomp-bpf-hook
containernetworking-plugins
aardvark-dns
netavark
fuse-overlayfs
crun
skopeo-tests
skopeo
crun (Red Hat package)
buildah (Red Hat package)
buildah-debugsource
buildah-debuginfo
buildah
cri-o (Red Hat package)
buildah-tests
conmon
container-selinux
crit
criu
criu-devel
criu-libs
python3-criu
podman (Red Hat package)
libslirp
libslirp-devel
python3-podman
podman-remote
podman-plugins
podman-gvproxy
podman-catatonit
podman
podman-tests
podman-docker
podman-debuginfo
podmansh
podman-remote-debuginfo
kernel (Red Hat package)
kernel-rt (Red Hat package)
cockpit-podman
How to mitigate CVE-2024-11218
IBM Qradar SIEM - update to 7.5.0 Update Pack 11 IF04
toolbox - update to 0.0.99.5-2.0.1
toolbox-tests - update to 0.0.99.5-2.0.1
udica - update to 0.2.6-21
containers-common - addressed in versions 0.61.1-1.fc40, 0.61.1-1.fc41
runc - update to 1.1.12-5.0.1
slirp4netns - update to 1.2.3-1
oci-seccomp-bpf-hook - update to 1.2.10-1
containernetworking-plugins - update to 1.4.0-5.0.1
aardvark-dns - update to 1.10.1-2.0.1
netavark - update to 1.10.3-1.0.1
fuse-overlayfs - update to 1.13-1.0.1
crun - update to 1.14.3-2
skopeo-tests - update to 1.14.5-3.0.1
skopeo - update to 1.14.5-3.0.1
crun (Red Hat package) - addressed in versions 1.17-2.rhaos4.16.el8, 1.17-2.rhaos4.16.el9, 1.19.1-1.rhaos4.17.el8
buildah (Red Hat package) - addressed in versions 1.23.5-1.rhaos4.12.el8, 1.23.5-1.rhaos4.12.el9, 1.26.9-1.el9_0, 1.29.5-1.el9_2, 1.29.5-1.rhaos4.15.el8, 1.29.5-1.rhaos4.15.el9, 1.33.12-2.el9_4, 1.37.6-1.el9_5
buildah-debugsource - update to 1.26.1-7
buildah-debuginfo - update to 1.26.1-7
buildah - update to 1.26.1-7
cri-o (Red Hat package) - addressed in versions 1.28.11-9.rhaos4.15.git815feb2.el8, 1.28.11-9.rhaos4.15.git815feb2.el9, 1.29.12-4.rhaos4.16.gitadc9401.el8, 1.29.12-4.rhaos4.16.gitadc9401.el9
buildah-tests - update to 1.33.12-1
buildah - update to 1.33.12-1
buildah - addressed in versions 1.35.5-150300.8.31.2, 1.35.5-150400.3.36.1, 1.35.5-150500.3.25.1
buildah - addressed in versions 1.38.1-1.fc40, 1.38.1-1.fc41
containers-common - update to 1-82.0.1
conmon - update to 2.1.10-1
container-selinux - update to 2.229.0-2
crit - update to 3.18-5.0.1
criu - update to 3.18-5.0.1
criu-devel - update to 3.18-5.0.1
criu-libs - update to 3.18-5.0.1
python3-criu - update to 3.18-5.0.1
podman (Red Hat package) - addressed in versions 4.2.0-6.el9_0, 4.2.0-13.rhaos4.12.el9, 4.4.1-9.rhaos4.12.el8, 4.4.1-22.el9_2, 4.4.1-22.rhaos4.14.el8, 4.4.1-22.rhaos4.14.el9, 4.9.4-13.rhaos4.16.el8, 4.9.4-15.rhaos4.16.el9, 4.9.4-17.el9_4, 5.2.2-2.rhaos4.17.el8, 5.2.2-2.rhaos4.17.el9, 5.2.2-13.el9_5
libslirp - update to 4.4.0-2
libslirp-devel - update to 4.4.0-2
python3-podman - update to 4.9.0-3
podman-remote - update to 4.9.4-19.0.1
podman-plugins - update to 4.9.4-19.0.1
podman-gvproxy - update to 4.9.4-19.0.1
podman-catatonit - update to 4.9.4-19.0.1
podman - update to 4.9.4-19.0.1
podman-tests - update to 4.9.4-19.0.1
podman-docker - update to 4.9.4-19.0.1
podman - addressed in versions 4.9.5-150300.9.43.1, 4.9.5-150400.4.35.1, 4.9.5-150500.3.31.1
podman-remote - addressed in versions 4.9.5-150300.9.43.1, 4.9.5-150400.4.35.1, 4.9.5-150500.3.31.1
podman-debuginfo - addressed in versions 4.9.5-150300.9.43.1, 4.9.5-150400.4.35.1, 4.9.5-150500.3.31.1
podman-docker - addressed in versions 4.9.5-150300.9.43.1, 4.9.5-150400.4.35.1, 4.9.5-150500.3.31.1
podmansh - addressed in versions 4.9.5-150300.9.43.1, 4.9.5-150400.4.35.1, 4.9.5-150500.3.31.1
podman-remote-debuginfo - addressed in versions 4.9.5-150300.9.43.1, 4.9.5-150400.4.35.1, 4.9.5-150500.3.31.1
Red Hat OpenShift Container Platform - addressed in versions 4.12.74, 4.14.48, 4.15.47, 4.16.33, 4.16.35, 4.17.15, 4.17.17, 4.17.20, 4.17.25, 4.18.4, 4.18.8
kernel (Red Hat package) - addressed in versions 4.18.0-372.141.1.el8_6, 5.14.0-284.104.1.el9_2, 5.14.0-284.108.1.el9_2
kernel-rt (Red Hat package) - addressed in versions 4.18.0-372.141.1.rt7.302.el8_6, 5.14.0-284.104.1.rt14.389.el9_2, 5.14.0-284.108.1.rt14.393.el9_2
podman - addressed in versions 5.3.2-1.fc40, 5.3.2-1.fc41
cockpit-podman - update to 84.1-1
External References
Related Security Bulletins
- Privilege escalation in Buildah
- Fedora 41 update for buildah, containers-common, podman
- Fedora 40 update for buildah, containers-common, podman
- SUSE update for podman
- SUSE update for buildah
- SUSE update for buildah
- SUSE update for buildah
- Red Hat Enterprise Linux 9 update for podman
- Red Hat Enterprise Linux 9 update for buildah
- Permissions, Privileges, and Access Controls in Red Hat OpenShift Container Platform 4.17 packages
- SUSE update for podman
- Red Hat Enterprise Linux 9 update for podman
- Red Hat Enterprise Linux 9 update for buildah
- Red Hat Enterprise Linux 9 update for buildah
- Red Hat Enterprise Linux 9 update for podman
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16 packages
- Red Hat Enterprise Linux 8 update for the container-tools:rhel8 module
- Red Hat Enterprise Linux 8 update for the container-tools:rhel8 module
- Red Hat Enterprise Linux 9 update for buildah
- Red Hat Enterprise Linux 9 update for podman
- Red Hat Enterprise Linux 8 update for the container-tools:rhel8 module
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Permissions, Privileges, and Access Controls in Red Hat OpenShift Container Platform 4.14
- SUSE update for podman
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Permissions, Privileges, and Access Controls in Red Hat OpenShift Container Platform 4.15 packages
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Permissions, Privileges, and Access Controls in Red Hat OpenShift Container Platform 4.12 packages
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.18
- Anolis OS update for container-tools:an8 module
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.18
- Multiple vulnerabilities in IBM QRadar SIEM
- openEuler 22.03 LTS SP4 update for buildah