Input validation error in buildah - CVE-2024-9341
Published: October 8, 2024
Vulnerability details
The vulnerability allows a remote user to gain access to sensitive information.
The vulnerability exists due to insufficient validation of user-supplied input. When FIPS mode is enabled on a system, container runtimes may incorrectly handle certain file paths due to improper validation in the containers/common Go library. This flaw allows an attacker to exploit symbolic links and trick the system into mounting sensitive host directories inside a container.
Affected software
Red Hat OpenShift Container Platform
Migration Toolkit for Containers
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise Server 15 SP4
Oracle Linux
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
SUSE Enterprise Storage
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
SUSE Linux Enterprise Server 15 SP4 LTSS
Containers Module
openSUSE Leap
openEuler
Fedora
IBM Concert Software
IBM Cloud Pak for Business Automation
Red Hat OpenShift Dev Spaces
Podman
Robotic Process Automation for Cloud Pak
Business Automation Insights
toolbox-tests
toolbox
udica
golang-github-prometheus-promu (Red Hat package)
butane (Red Hat package)
containers-common
runc (Red Hat package)
runc
slirp4netns
oci-seccomp-bpf-hook
containernetworking-plugins (Red Hat package)
containernetworking-plugins
skopeo (Red Hat package)
aardvark-dns
netavark
fuse-overlayfs
crun
skopeo
skopeo-tests
crun (Red Hat package)
buildah (Red Hat package)
cri-tools (Red Hat package)
cri-o (Red Hat package)
buildah-debugsource
buildah
buildah-debuginfo
buildah-tests
conmon (Red Hat package)
conmon
haproxy (Red Hat package)
ignition (Red Hat package)
container-selinux (Red Hat package)
container-selinux
kata-containers (Red Hat package)
criu-libs
criu
python3-criu
crit
criu-devel
podman (Red Hat package)
libslirp
libslirp-devel
python3-podman
podman-gvproxy
podman-plugins
podman-debugsource
podman
podman-debuginfo
podman-remote
podman-tests
podmansh
podman-docker
podman-help
podman-catatonit
podman-remote-debuginfo
openshift-ansible (Red Hat package)
openshift (Red Hat package)
openshift-kuryr (Red Hat package)
openshift4-aws-iso (Red Hat package)
openshift-clients (Red Hat package)
ose-azure-acr-image-credential-provider (Red Hat package)
ose-gcp-gcr-image-credential-provider (Red Hat package)
ose-aws-ecr-image-credential-provider (Red Hat package)
kernel-rt (Red Hat package)
kernel (Red Hat package)
openstack-ironic-python-agent (Red Hat package)
openstack-ironic (Red Hat package)
cockpit-podman
How to mitigate CVE-2024-9341
IBM Concert Software - update to 1.0.5
Red Hat OpenShift Container Platform - addressed in versions 4.12.68, 4.13.53, 4.14.39, 4.15.37, 4.15.38, 4.16.18, 4.16.19, 4.16.24, 4.17.1, 4.17.2, 4.17.8
Podman - update to 5.2.4
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.21, 23.0.20.2
Business Automation Insights - addressed in versions 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2
IBM Cloud Pak for Business Automation - addressed in versions 24.0.1-IF006, 25.0.0-IF003
toolbox-tests - update to 0.0.99.5-2.0.1
toolbox - update to 0.0.99.5-2.0.1
udica - update to 0.2.6-21
golang-github-prometheus-promu (Red Hat package) - update to 0.15.0-18.gitd5383c5.el8
butane (Red Hat package) - addressed in versions 0.16.0-5.rhaos4.12.el8, 0.20.0-4.rhaos4.15.el8, 0.21.0-4.rhaos4.16.el8, 0.22.0-1.rhaos4.17.el8
containers-common - update to 0.60.4-4.fc41
runc (Red Hat package) - addressed in versions 1.1.6-9.rhaos4.12.el8, 1.1.14-1.rhaos4.17.el8, 1.1.14-1.rhaos4.17.el9, 1.1.14-2.rhaos4.13.el8, 1.1.14-2.rhaos4.13.el9, 1.1.14-2.rhaos4.15.el8, 1.1.14-2.rhaos4.15.el9, 1.1.14-3.rhaos4.16.el8, 1.1.14-3.rhaos4.16.el9
runc - update to 1.1.12-5.0.1
slirp4netns - update to 1.2.3-1
oci-seccomp-bpf-hook - update to 1.2.10-1
containernetworking-plugins (Red Hat package) - addressed in versions 1.4.0-4.rhaos4.12.el8, 1.4.0-4.rhaos4.15.el8, 1.4.0-5.rhaos4.13.el8, 1.4.0-5.rhaos4.16.el8
containernetworking-plugins - update to 1.4.0-5.0.1
Migration Toolkit for Containers - update to 1.8.5
skopeo (Red Hat package) - addressed in versions 1.9.4-7.rhaos4.12.el8, 1.9.4-7.rhaos4.12.el9, 1.11.3-4.rhaos4.13.el8, 1.11.3-4.rhaos4.13.el9, 1.11.3-5.rhaos4.15.el8, 1.11.3-6.rhaos4.15.el9, 1.14.5-3.rhaos4.16.el8, 1.14.5-3.rhaos4.16.el9
aardvark-dns - update to 1.10.1-2.0.1
netavark - update to 1.10.3-1.0.1
fuse-overlayfs - update to 1.13-1.0.1
crun - update to 1.14.3-2
skopeo - update to 1.14.5-3.0.1
skopeo-tests - update to 1.14.5-3.0.1
crun (Red Hat package) - addressed in versions 1.17-1.rhaos4.17.el8, 1.17-1.rhaos4.17.el9
buildah (Red Hat package) - addressed in versions 1.23.4-8.rhaos4.12.el8, 1.23.4-8.rhaos4.12.el9, 1.29.1-5.rhaos4.13.el9, 1.29.1-24.rhaos4.15.el8, 1.29.1-24.rhaos4.15.el9, 1.33.7-4.rhaos4.16.el8, 1.33.7-4.rhaos4.16.el9, 1.33.9-1.el9_4, 1.37.5-1.el9_5
cri-tools (Red Hat package) - addressed in versions 1.25.0-5.el8, 1.25.0-5.el9, 1.26.0-7.el8, 1.26.0-7.el9, 1.28.0-7.el8, 1.28.0-7.el9, 1.29.0-6.el8, 1.29.0-6.el9
cri-o (Red Hat package) - addressed in versions 1.25.5-5.rhaos4.12.git53dc492.el9, 1.25.5-30.rhaos4.12.git53dc492.el8, 1.26.5-26.rhaos4.13.giteb3d487.el8, 1.26.5-26.rhaos4.13.giteb3d487.el9, 1.27.8-10.rhaos4.14.git807f92c.el8, 1.27.8-10.rhaos4.14.git807f92c.el9, 1.28.11-5.rhaos4.15.git35a2431.el8, 1.28.11-5.rhaos4.15.git35a2431.el9, 1.29.9-5.rhaos4.16.git34690b9.el8, 1.29.9-5.rhaos4.16.git34690b9.el9, 1.30.6-3.rhaos4.17.git49b5172.el8, 1.30.6-3.rhaos4.17.git49b5172.el9
buildah-debugsource - addressed in versions 1.26.1-7, 1.34.1-10
buildah - addressed in versions 1.26.1-7, 1.34.1-10
buildah-debuginfo - addressed in versions 1.26.1-7, 1.34.1-10
buildah-tests - update to 1.33.10-1
buildah - update to 1.33.10-1
buildah-tests - update to 1.34.1-10
buildah - addressed in versions 1.35.4-150300.8.28.3, 1.35.4-150400.3.33.1, 1.35.4-150500.3.13.1
buildah - addressed in versions 1.37.4-1.fc40, 1.37.4-1.fc41, 1.37.5-1.fc40, 1.37.5-1.fc41
containers-common - update to 1-82.0.1
conmon (Red Hat package) - addressed in versions 2.1.2-8.rhaos4.12.el8, 2.1.2-9.rhaos4.12.el9, 2.1.7-5.rhaos4.13.el8, 2.1.7-5.rhaos4.13.el9, 2.1.7-10.rhaos4.15.el8, 2.1.7-15.rhaos4.15.el9, 2.1.10-5.rhaos4.16.el8, 2.1.10-5.rhaos4.16.el9
conmon - update to 2.1.10-1
haproxy (Red Hat package) - addressed in versions 2.2.24-5.rhaos4.12.el8, 2.2.24-5.rhaos4.13.el8
ignition (Red Hat package) - addressed in versions 2.14.0-8.rhaos4.12.el9, 2.14.0-10.rhaos4.12.el8, 2.15.0-10.rhaos4.13.el9, 2.16.2-6.rhaos4.15.el9, 2.18.0-5.rhaos4.16.el9
container-selinux (Red Hat package) - addressed in versions 2.228.1-1.rhaos4.12.el8, 2.228.1-1.rhaos4.14.el8, 2.228.1-1.rhaos4.14.el9, 2.231.0-4.rhaos4.17.el8, 2.231.0-4.rhaos4.17.el9
container-selinux - update to 2.229.0-2
kata-containers (Red Hat package) - update to 3.7.0-3.rhaos4.17.el9
Red Hat OpenShift Dev Spaces - update to 3.17.0
criu-libs - update to 3.18-5.0.1
criu - update to 3.18-5.0.1
python3-criu - update to 3.18-5.0.1
crit - update to 3.18-5.0.1
criu-devel - update to 3.18-5.0.1
podman (Red Hat package) - addressed in versions 4.2.0-12.rhaos4.12.el9, 4.4.1-8.rhaos4.12.el8, 4.4.1-15.rhaos4.13.el8, 4.4.1-16.rhaos4.13.el9, 4.4.1-31.rhaos4.15.el8, 4.4.1-31.rhaos4.15.el9, 4.9.4-10.rhaos4.16.el8, 4.9.4-12.rhaos4.16.el9, 4.9.4-13.el9_4, 5.2.2-9.el9_5, 5.2.3-1.rhaos4.17.el8, 5.2.3-1.rhaos4.17.el9
libslirp - update to 4.4.0-2
libslirp-devel - update to 4.4.0-2
python3-podman - update to 4.9.0-2
podman-gvproxy - update to 4.9.4-13
podman-plugins - update to 4.9.4-13
podman-debugsource - update to 4.9.4-13
podman - update to 4.9.4-13
podman-debuginfo - update to 4.9.4-13
podman-remote - update to 4.9.4-13
podman-tests - update to 4.9.4-13
podmansh - update to 4.9.4-13
podman-docker - update to 4.9.4-13
podman-help - update to 4.9.4-13
podman-catatonit - update to 4.9.4-15.0.1
podman-gvproxy - update to 4.9.4-15.0.1
podman-plugins - update to 4.9.4-15.0.1
podman-remote - update to 4.9.4-15.0.1
podman - update to 4.9.4-15.0.1
podman-tests - update to 4.9.4-15.0.1
podman-docker - update to 4.9.4-15.0.1
podman-debuginfo - addressed in versions 4.9.5-150300.9.43.1, 4.9.5-150400.4.35.1, 4.9.5-150500.3.18.1
podman-docker - addressed in versions 4.9.5-150300.9.43.1, 4.9.5-150400.4.35.1, 4.9.5-150500.3.18.1
podman - addressed in versions 4.9.5-150300.9.43.1, 4.9.5-150400.4.35.1, 4.9.5-150500.3.18.1
podman-remote - addressed in versions 4.9.5-150300.9.43.1, 4.9.5-150400.4.35.1, 4.9.5-150500.3.18.1
podmansh - addressed in versions 4.9.5-150300.9.43.1, 4.9.5-150400.4.35.1, 4.9.5-150500.3.18.1
podman-remote-debuginfo - addressed in versions 4.9.5-150300.9.43.1, 4.9.5-150400.4.35.1, 4.9.5-150500.3.18.1
openshift-ansible (Red Hat package) - addressed in versions 4.12.0-202410181935.p0.gd97dd6f.assembly.stream.el8, 4.13.0-202410181847.p0.g1397e80.assembly.stream.el8, 4.13.0-202410181847.p0.g1397e80.assembly.stream.el9, 4.15.0-202410181710.p0.g41f6580.assembly.stream.el8, 4.15.0-202410181710.p0.g41f6580.assembly.stream.el9, 4.16.0-202410172045.p0.g06f35b9.assembly.stream.el8, 4.16.0-202410172045.p0.g06f35b9.assembly.stream.el9
openshift (Red Hat package) - addressed in versions 4.12.0-202410181935.p0.g1eb8682.assembly.stream.el8, 4.12.0-202410181935.p0.g1eb8682.assembly.stream.el9, 4.13.0-202410181847.p0.g53fd427.assembly.stream.el8, 4.13.0-202410181847.p0.g53fd427.assembly.stream.el9, 4.15.0-202410232006.p0.g502c5ce.assembly.stream.el8, 4.15.0-202410232006.p0.g502c5ce.assembly.stream.el9, 4.16.0-202410172045.p0.g632b078.assembly.stream.el8, 4.16.0-202410172045.p0.g632b078.assembly.stream.el9, 4.17.0-202410020505.p0.g9f67343.assembly.stream.el8, 4.17.0-202410020505.p0.g9f67343.assembly.stream.el9
openshift-kuryr (Red Hat package) - addressed in versions 4.12.0-202410181935.p0.g8fd2f8b.assembly.stream.el8, 4.13.0-202410181847.p0.g36754b7.assembly.stream.el8
openshift4-aws-iso (Red Hat package) - addressed in versions 4.12.0-202410181935.p0.gd2acdd5.assembly.stream.el8, 4.13.0-202410181847.p0.gd2acdd5.assembly.stream.el8, 4.15.0-202410181710.p0.gd2acdd5.assembly.stream.el8, 4.16.0-202410172045.p0.gd2acdd5.assembly.stream.el8
openshift-clients (Red Hat package) - addressed in versions 4.12.0-202410181935.p0.gd691257.assembly.stream.el8, 4.12.0-202410181935.p0.gd691257.assembly.stream.el9, 4.13.0-202410181847.p0.gd192e90.assembly.stream.el8, 4.13.0-202410181847.p0.gd192e90.assembly.stream.el9, 4.15.0-202410181710.p0.g8231637.assembly.stream.el8, 4.15.0-202410181710.p0.g8231637.assembly.stream.el9, 4.16.0-202410172045.p0.gcf533b5.assembly.stream.el8, 4.16.0-202410172045.p0.gcf533b5.assembly.stream.el9, 4.17.0-202410031034.p0.g9566b8e.assembly.stream.el8, 4.17.0-202410031034.p0.g9566b8e.assembly.stream.el9
ose-azure-acr-image-credential-provider (Red Hat package) - addressed in versions 4.15.0-202410181710.p0.g0d799a2.assembly.stream.el8, 4.15.0-202410181710.p0.g0d799a2.assembly.stream.el9, 4.16.0-202410172045.p0.g0e95532.assembly.stream.el8, 4.16.0-202410172045.p0.g0e95532.assembly.stream.el9
ose-gcp-gcr-image-credential-provider (Red Hat package) - addressed in versions 4.15.0-202410181710.p0.gfc50272.assembly.stream.el8, 4.15.0-202410181710.p0.gfc50272.assembly.stream.el9, 4.16.0-202410172045.p0.g26b43df.assembly.stream.el8, 4.16.0-202410172045.p0.g26b43df.assembly.stream.el9
ose-aws-ecr-image-credential-provider (Red Hat package) - addressed in versions 4.15.0-202410181710.p0.gfd77d92.assembly.stream.el8, 4.15.0-202410181710.p0.gfd77d92.assembly.stream.el9, 4.16.0-202410172045.p0.ga53e9de.assembly.stream.el8, 4.16.0-202410172045.p0.ga53e9de.assembly.stream.el9
kernel-rt (Red Hat package) - addressed in versions 4.18.0-372.127.1.rt7.287.el8_6, 5.14.0-284.90.1.rt14.375.el9_2
podman - addressed in versions 5.2.4-1.fc40, 5.2.4-1.fc41, 5.2.5-1.fc40, 5.2.5-1.fc41
kernel (Red Hat package) - addressed in versions 5.14.0-284.90.1.el9_2, 5.14.0-427.40.1.el9_4
openstack-ironic-python-agent (Red Hat package) - update to 9.0.1-0.20240913135525.2b2dd8f.el9
openstack-ironic (Red Hat package) - update to 21.0.1-0.20240913135525.114badc.el9
cockpit-podman - update to 84.1-1
External References
Related Security Bulletins
- Multiple vulnerabilities in buildah
- libpod update for Buildah
- Fedora 41 update for buildah, podman
- SUSE update for buildah
- SUSE update for podman
- Fedora 40 update for buildah, podman
- Red Hat Enterprise Linux 9 update for podman
- Multiple vulnerabilities in Oracle Linux
- Input validation error in Red Hat OpenShift Container Platform 4.17 packages
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Fedora 41 update for buildah, containers-common, podman
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Input validation error in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16 packages
- Fedora 40 update for buildah, podman
- Red Hat Enterprise Linux 9 update for buildah
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15 packages
- Red Hat Enterprise Linux 8 update for the container-tools:rhel8 module
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13 packages
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Red Hat Enterprise Linux 9 update for podman
- Red Hat Enterprise Linux 9 update for buildah
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- SUSE update for buildah
- Multiple vulnerabilities in Red Hat OpenShift Dev Spaces 3.17
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in Migration Toolkit for Containers 1.8
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- SUSE update for buildah
- openEuler 24.03 LTS SP1 update for podman
- openEuler 24.03 LTS update for podman
- SUSE update for podman
- SUSE update for podman
- Multiple vulnerabilities in IBM Concert Software
- Anolis OS update for container-tools:an8 module
- Multiple vulnerabilities in IBM Robotic Process Automation for Cloud Pak
- openEuler 24.03 LTS SP1 update for buildah
- openEuler 24.03 LTS update for buildah
- openEuler 24.03 LTS SP2 update for buildah
- openEuler 22.03 LTS SP4 update for buildah
- Multiple vulnerabilities in IBM Business Automation Insights
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation