Input validation error in buildah - CVE-2024-9407

 

Input validation error in buildah - CVE-2024-9407

Published: October 8, 2024


Vulnerability identifier: #VU98140
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-9407
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to gain access to sensitive information.

A vulnerability exists in the bind-propagation option of the Dockerfile RUN --mount instruction. The system does not properly validate the input passed to this option, allowing users to pass arbitrary parameters to the mount instruction. This issue can be exploited to mount sensitive directories from the host into a container during the build process and, in some cases, modify the contents of those mounted files.

Even if SELinux is used, this vulnerability can bypass its protection by allowing the source directory to be relabeled to give the container access to host files.


Affected software

buildah
Red Hat OpenShift Container Platform
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
SUSE Enterprise Storage
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Anolis OS
SUSE Linux Enterprise Server 15 SP4 LTSS
Containers Module
openSUSE Leap
openEuler
Fedora
Podman
toolbox-tests
toolbox
udica
runc
slirp4netns
oci-seccomp-bpf-hook
containernetworking-plugins
aardvark-dns
netavark
fuse-overlayfs
crun
skopeo
skopeo-tests
buildah
buildah-debuginfo
buildah-debugsource
buildah-tests
buildah (Red Hat package)
containers-common
conmon
container-selinux
crit
criu
criu-devel
criu-libs
python3-criu
libslirp-devel
libslirp
python3-podman
podmansh
podman-help
podman-docker
podman-tests
podman-remote
podman-plugins
podman-gvproxy
podman-debugsource
podman-debuginfo
podman
podman-catatonit
podman (Red Hat package)
podman-remote-debuginfo
cockpit-podman

How to mitigate CVE-2024-9407

Install updates from vendor's website.

buildah - update to 1.37.4
Podman - update to 5.2.4
toolbox-tests - update to 0.0.99.5-2.0.1
toolbox - update to 0.0.99.5-2.0.1
udica - update to 0.2.6-21
runc - update to 1.1.12-5.0.1
slirp4netns - update to 1.2.3-1
oci-seccomp-bpf-hook - update to 1.2.10-1
containernetworking-plugins - update to 1.4.0-5.0.1
aardvark-dns - update to 1.10.1-2.0.1
netavark - update to 1.10.3-1.0.1
fuse-overlayfs - update to 1.13-1.0.1
crun - update to 1.14.3-2
skopeo - update to 1.14.5-3.0.1
skopeo-tests - update to 1.14.5-3.0.1
buildah - addressed in versions 1.26.1-7, 1.34.1-10
buildah-debuginfo - addressed in versions 1.26.1-7, 1.34.1-10
buildah-debugsource - addressed in versions 1.26.1-7, 1.34.1-10
buildah-tests - update to 1.33.10-1
buildah - update to 1.33.10-1
buildah (Red Hat package) - addressed in versions 1.33.11-1.el9_4, 1.37.5-1.el9_5
buildah-tests - update to 1.34.1-10
buildah - addressed in versions 1.35.4-150300.8.28.3, 1.35.4-150400.3.33.1, 1.35.4-150500.3.13.1, 1.35.5-150300.8.31.2, 1.35.5-150400.3.36.1
buildah - addressed in versions 1.37.4-1.fc40, 1.37.4-1.fc41, 1.37.5-1.fc40
containers-common - update to 1-82.0.1
conmon - update to 2.1.10-1
container-selinux - update to 2.229.0-2
crit - update to 3.18-5.0.1
criu - update to 3.18-5.0.1
criu-devel - update to 3.18-5.0.1
criu-libs - update to 3.18-5.0.1
python3-criu - update to 3.18-5.0.1
libslirp-devel - update to 4.4.0-2
libslirp - update to 4.4.0-2
python3-podman - update to 4.9.0-2
podmansh - update to 4.9.4-13
podman-help - update to 4.9.4-13
podman-docker - update to 4.9.4-13
podman-tests - update to 4.9.4-13
podman-remote - update to 4.9.4-13
podman-plugins - update to 4.9.4-13
podman-gvproxy - update to 4.9.4-13
podman-debugsource - update to 4.9.4-13
podman-debuginfo - update to 4.9.4-13
podman - update to 4.9.4-13
podman-docker - update to 4.9.4-15.0.1
podman-tests - update to 4.9.4-15.0.1
podman-remote - update to 4.9.4-15.0.1
podman-plugins - update to 4.9.4-15.0.1
podman-gvproxy - update to 4.9.4-15.0.1
podman-catatonit - update to 4.9.4-15.0.1
podman - update to 4.9.4-15.0.1
podman (Red Hat package) - addressed in versions 4.9.4-16.el9_4, 5.2.2-9.el9_5
podman-remote-debuginfo - addressed in versions 4.9.5-150300.9.43.1, 4.9.5-150400.4.35.1, 4.9.5-150500.3.25.1
podmansh - addressed in versions 4.9.5-150300.9.43.1, 4.9.5-150400.4.35.1, 4.9.5-150500.3.25.1
podman-remote - addressed in versions 4.9.5-150300.9.43.1, 4.9.5-150400.4.35.1, 4.9.5-150500.3.25.1
podman - addressed in versions 4.9.5-150300.9.43.1, 4.9.5-150400.4.35.1, 4.9.5-150500.3.25.1
podman-debuginfo - addressed in versions 4.9.5-150300.9.43.1, 4.9.5-150400.4.35.1, 4.9.5-150500.3.25.1
podman-docker - addressed in versions 4.9.5-150300.9.43.1, 4.9.5-150400.4.35.1, 4.9.5-150500.3.25.1
Red Hat OpenShift Container Platform - addressed in versions 4.16.23, 4.16.24
podman - addressed in versions 5.2.4-1.fc40, 5.2.4-1.fc41, 5.2.5-1.fc40
cockpit-podman - update to 84.1-1

External References

Related Security Bulletins