UNIX symbolic link following in Podman - CVE-2024-9676
Published: October 18, 2024 / Updated: October 22, 2024
Vulnerability details
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to a symlink following issue when running a malicious image using an automatically assigned user namespace (`--userns=auto` in Podman and Buildah). A local user can create a symbolic link to an arbitrary file on the system, force the library to read it and perform a denial of service (DoS) attack.
Affected software
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
SUSE Enterprise Storage
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Fedora
SUSE Linux Enterprise Server 15 SP4 LTSS
Containers Module
openSUSE Leap
openEuler
CRI-O
Multicluster Engine for Kubernetes
OpenShift Data Foundation (formerly OpenShift Container Storage)
buildah
Red Hat OpenShift Container Platform
Migration Toolkit for Containers
Storage
Red Hat OpenShift Dev Spaces
toolbox-tests
toolbox
udica
golang-github-prometheus-promu (Red Hat package)
butane (Red Hat package)
containers-common
skopeo
skopeo-debuginfo
skopeo-debugsource
runc (Red Hat package)
runc
slirp4netns
podman-tui
oci-seccomp-bpf-hook
containernetworking-plugins (Red Hat package)
containernetworking-plugins
skopeo (Red Hat package)
aardvark-dns
netavark
fuse-overlayfs
skopeo-tests
crun
buildah (Red Hat package)
cri-tools (Red Hat package)
cri-o (Red Hat package)
buildah
buildah-debugsource
buildah-debuginfo
buildah-tests
conmon (Red Hat package)
conmon
haproxy (Red Hat package)
ignition (Red Hat package)
container-selinux (Red Hat package)
container-selinux
criu-devel
criu
crit
python3-criu
criu-libs
podman (Red Hat package)
libslirp
libslirp-devel
libreswan (Red Hat package)
python3-podman
podman
podman-debuginfo
podman-debugsource
podman-gvproxy
podman-remote
podman-plugins
podman-tests
podmansh
podman-docker
podman-help
podman-catatonit
podman-remote-debuginfo
openshift-ansible (Red Hat package)
openshift (Red Hat package)
openshift-kuryr (Red Hat package)
openshift4-aws-iso (Red Hat package)
openshift-clients (Red Hat package)
ose-aws-ecr-image-credential-provider (Red Hat package)
ose-azure-acr-image-credential-provider (Red Hat package)
ose-gcp-gcr-image-credential-provider (Red Hat package)
kernel-rt (Red Hat package)
kernel (Red Hat package)
openstack-ironic-python-agent (Red Hat package)
openstack-ironic (Red Hat package)
cockpit-podman
How to mitigate CVE-2024-9676
CRI-O - update to 1.28.11
buildah - update to 1.37.5
Storage - update to 1.55.1
Red Hat OpenShift Container Platform - addressed in versions 4.12.68, 4.13.53, 4.14.40, 4.15.37, 4.15.38, 4.15.47, 4.16.19, 4.16.20, 4.16.23, 4.16.24, 4.16.38, 4.17.3, 4.17.4, 4.17.15
toolbox-tests - update to 0.0.99.5-2.0.1
toolbox - update to 0.0.99.5-2.0.1
udica - update to 0.2.6-21
golang-github-prometheus-promu (Red Hat package) - update to 0.15.0-18.gitd5383c5.el8
butane (Red Hat package) - addressed in versions 0.16.0-5.rhaos4.12.el8, 0.19.0-4.rhaos4.14.el8, 0.20.0-4.rhaos4.15.el8
containers-common - update to 0.60.4-4.fc41
containers-common - update to 1.1.0-17
skopeo - addressed in versions 1.1.0-17, 1.8.0-11, 1.14.2-9
skopeo-debuginfo - addressed in versions 1.1.0-17, 1.8.0-11, 1.14.2-9
skopeo-debugsource - addressed in versions 1.1.0-17, 1.8.0-11, 1.14.2-9
runc (Red Hat package) - addressed in versions 1.1.6-9.rhaos4.12.el8, 1.1.14-2.rhaos4.13.el8, 1.1.14-2.rhaos4.13.el9, 1.1.14-2.rhaos4.14.el8, 1.1.14-2.rhaos4.14.el9, 1.1.14-2.rhaos4.15.el8, 1.1.14-2.rhaos4.15.el9
runc - update to 1.1.12-5.0.1
slirp4netns - update to 1.2.3-1
podman-tui - addressed in versions 1.2.3-1.el9, 1.2.3-1.fc40, 1.2.3-1.fc41
oci-seccomp-bpf-hook - update to 1.2.10-1
containernetworking-plugins (Red Hat package) - addressed in versions 1.4.0-4.rhaos4.12.el8, 1.4.0-4.rhaos4.14.el8, 1.4.0-4.rhaos4.15.el8, 1.4.0-5.rhaos4.13.el8
containernetworking-plugins - update to 1.4.0-5.0.1
Migration Toolkit for Containers - update to 1.8.5
skopeo (Red Hat package) - addressed in versions 1.9.4-7.rhaos4.12.el8, 1.9.4-7.rhaos4.12.el9, 1.11.3-4.rhaos4.13.el8, 1.11.3-4.rhaos4.13.el9, 1.11.3-4.rhaos4.14.el8, 1.11.3-4.rhaos4.14.el9, 1.11.3-5.rhaos4.15.el8, 1.11.3-6.rhaos4.15.el9
aardvark-dns - update to 1.10.1-2.0.1
netavark - update to 1.10.3-1.0.1
fuse-overlayfs - update to 1.13-1.0.1
skopeo-tests - update to 1.14.2-9
crun - update to 1.14.3-2
skopeo-tests - update to 1.14.5-3.0.1
skopeo - update to 1.14.5-3.0.1
buildah (Red Hat package) - addressed in versions 1.23.4-8.rhaos4.12.el8, 1.23.4-8.rhaos4.12.el9, 1.29.1-5.rhaos4.13.el9, 1.29.1-13.rhaos4.14.el8, 1.29.1-13.rhaos4.14.el9, 1.29.1-24.rhaos4.15.el8, 1.29.1-24.rhaos4.15.el9, 1.33.11-1.el9_4, 1.37.5-1.el9_5
cri-tools (Red Hat package) - addressed in versions 1.25.0-5.el8, 1.25.0-5.el9, 1.26.0-7.el8, 1.26.0-7.el9, 1.27.0-6.el8, 1.27.0-6.el9, 1.28.0-7.el8, 1.28.0-7.el9
cri-o (Red Hat package) - addressed in versions 1.25.5-5.rhaos4.12.git53dc492.el9, 1.25.5-30.rhaos4.12.git53dc492.el8, 1.26.5-26.rhaos4.13.giteb3d487.el8, 1.26.5-26.rhaos4.13.giteb3d487.el9, 1.27.8-12.rhaos4.14.git7597c43.el8, 1.27.8-12.rhaos4.14.git7597c43.el9, 1.28.11-5.rhaos4.15.git35a2431.el8, 1.28.11-5.rhaos4.15.git35a2431.el9, 1.29.9-6.rhaos4.16.gite7bd45a.el8, 1.29.9-6.rhaos4.16.gite7bd45a.el9, 1.30.6-6.rhaos4.17.git6ac6e96.el8, 1.30.6-6.rhaos4.17.git6ac6e96.el9, 1.30.7-2.rhaos4.17.git2391edc.el8, 1.30.7-2.rhaos4.17.git2391edc.el9
buildah - addressed in versions 1.26.1-13, 1.34.1-15
buildah-debugsource - addressed in versions 1.26.1-13, 1.34.1-15
buildah-debuginfo - addressed in versions 1.26.1-13, 1.34.1-15
buildah-tests - update to 1.33.11-1
buildah - update to 1.33.11-1
buildah-tests - update to 1.34.1-15
buildah - addressed in versions 1.35.4-150300.8.28.3, 1.35.4-150400.3.33.1, 1.35.4-150500.3.19.1
buildah - addressed in versions 1.37.5-1.fc40, 1.37.5-1.fc41
containers-common - update to 1-82.0.1
conmon (Red Hat package) - addressed in versions 2.1.2-8.rhaos4.12.el8, 2.1.2-9.rhaos4.12.el9, 2.1.7-5.rhaos4.13.el8, 2.1.7-5.rhaos4.13.el9, 2.1.7-6.rhaos4.14.el8, 2.1.7-6.rhaos4.14.el9, 2.1.7-10.rhaos4.15.el8, 2.1.7-15.rhaos4.15.el9
conmon - update to 2.1.10-1
haproxy (Red Hat package) - addressed in versions 2.2.24-5.rhaos4.12.el8, 2.2.24-5.rhaos4.13.el8
Multicluster Engine for Kubernetes - addressed in versions 2.3.8, 2.6.4
ignition (Red Hat package) - addressed in versions 2.14.0-8.rhaos4.12.el9, 2.14.0-10.rhaos4.12.el8, 2.15.0-10.rhaos4.13.el9, 2.16.2-5.rhaos4.14.el9, 2.16.2-6.rhaos4.15.el9
container-selinux (Red Hat package) - update to 2.228.1-1.rhaos4.12.el8
container-selinux - update to 2.229.0-2
Red Hat OpenShift Dev Spaces - update to 3.17.0
criu-devel - update to 3.18-5.0.1
criu - update to 3.18-5.0.1
crit - update to 3.18-5.0.1
python3-criu - update to 3.18-5.0.1
criu-libs - update to 3.18-5.0.1
podman (Red Hat package) - addressed in versions 4.2.0-12.rhaos4.12.el9, 4.4.1-8.rhaos4.12.el8, 4.4.1-15.rhaos4.13.el8, 4.4.1-16.rhaos4.13.el9, 4.4.1-21.rhaos4.14.el8, 4.4.1-21.rhaos4.14.el9, 4.4.1-31.rhaos4.15.el8, 4.4.1-31.rhaos4.15.el9, 4.9.4-12.rhaos4.16.el8, 4.9.4-14.rhaos4.16.el9, 4.9.4-16.el9_4, 5.2.2-1.rhaos4.17.el8, 5.2.2-1.rhaos4.17.el9, 5.2.2-9.el9_5
libslirp - update to 4.4.0-2
libslirp-devel - update to 4.4.0-2
libreswan (Red Hat package) - update to 4.5-1.el9
python3-podman - update to 4.9.0-3
podman - update to 4.9.4-13
podman-debuginfo - update to 4.9.4-13
podman-debugsource - update to 4.9.4-13
podman-gvproxy - update to 4.9.4-13
podman-remote - update to 4.9.4-13
podman-plugins - update to 4.9.4-13
podman-tests - update to 4.9.4-13
podmansh - update to 4.9.4-13
podman-docker - update to 4.9.4-13
podman-help - update to 4.9.4-13
podman-docker - update to 4.9.4-18.0.1
podman - update to 4.9.4-18.0.1
podman-catatonit - update to 4.9.4-18.0.1
podman-gvproxy - update to 4.9.4-18.0.1
podman-plugins - update to 4.9.4-18.0.1
podman-tests - update to 4.9.4-18.0.1
podman-remote - update to 4.9.4-18.0.1
podmansh - addressed in versions 4.9.5-150300.9.43.1, 4.9.5-150400.4.35.1, 4.9.5-150500.3.28.1
podman-remote-debuginfo - addressed in versions 4.9.5-150300.9.43.1, 4.9.5-150400.4.35.1, 4.9.5-150500.3.28.1
podman-remote - addressed in versions 4.9.5-150300.9.43.1, 4.9.5-150400.4.35.1, 4.9.5-150500.3.28.1
podman - addressed in versions 4.9.5-150300.9.43.1, 4.9.5-150400.4.35.1, 4.9.5-150500.3.28.1
podman-debuginfo - addressed in versions 4.9.5-150300.9.43.1, 4.9.5-150400.4.35.1, 4.9.5-150500.3.28.1
podman-docker - addressed in versions 4.9.5-150300.9.43.1, 4.9.5-150400.4.35.1, 4.9.5-150500.3.28.1
openshift-ansible (Red Hat package) - addressed in versions 4.12.0-202410181935.p0.gd97dd6f.assembly.stream.el8, 4.13.0-202410181847.p0.g1397e80.assembly.stream.el8, 4.13.0-202410181847.p0.g1397e80.assembly.stream.el9, 4.14.0-202410181711.p0.g846e89b.assembly.stream.el8, 4.14.0-202410181711.p0.g846e89b.assembly.stream.el9, 4.15.0-202410181710.p0.g41f6580.assembly.stream.el8, 4.15.0-202410181710.p0.g41f6580.assembly.stream.el9
openshift (Red Hat package) - addressed in versions 4.12.0-202410181935.p0.g1eb8682.assembly.stream.el8, 4.12.0-202410181935.p0.g1eb8682.assembly.stream.el9, 4.13.0-202410181847.p0.g53fd427.assembly.stream.el8, 4.13.0-202410181847.p0.g53fd427.assembly.stream.el9, 4.14.0-202410181711.p0.g03a907c.assembly.stream.el8, 4.14.0-202410181711.p0.g03a907c.assembly.stream.el9, 4.15.0-202410232006.p0.g502c5ce.assembly.stream.el8, 4.15.0-202410232006.p0.g502c5ce.assembly.stream.el9, 4.16.0-202410231936.p0.g5865c5b.assembly.stream.el8, 4.16.0-202410231936.p0.g5865c5b.assembly.stream.el9
openshift-kuryr (Red Hat package) - addressed in versions 4.12.0-202410181935.p0.g8fd2f8b.assembly.stream.el8, 4.13.0-202410181847.p0.g36754b7.assembly.stream.el8, 4.14.0-202410181711.p0.g8926a29.assembly.stream.el8
openshift4-aws-iso (Red Hat package) - addressed in versions 4.12.0-202410181935.p0.gd2acdd5.assembly.stream.el8, 4.13.0-202410181847.p0.gd2acdd5.assembly.stream.el8, 4.14.0-202410181711.p0.gd2acdd5.assembly.stream.el8, 4.15.0-202410181710.p0.gd2acdd5.assembly.stream.el8
openshift-clients (Red Hat package) - addressed in versions 4.12.0-202410181935.p0.gd691257.assembly.stream.el8, 4.12.0-202410181935.p0.gd691257.assembly.stream.el9, 4.13.0-202410181847.p0.gd192e90.assembly.stream.el8, 4.13.0-202410181847.p0.gd192e90.assembly.stream.el9, 4.14.0-202410181711.p0.g44b3ac2.assembly.stream.el8, 4.14.0-202410181711.p0.g44b3ac2.assembly.stream.el9, 4.15.0-202410181710.p0.g8231637.assembly.stream.el8, 4.15.0-202410181710.p0.g8231637.assembly.stream.el9, 4.17.0-202410161505.p0.g897ef0b.assembly.stream.el8, 4.17.0-202410161505.p0.g897ef0b.assembly.stream.el9, 4.17.0-202410231505.p0.gdde885f.assembly.stream.el8, 4.17.0-202410231505.p0.gdde885f.assembly.stream.el9
ose-aws-ecr-image-credential-provider (Red Hat package) - addressed in versions 4.14.0-202410181711.p0.g9a7820e.assembly.stream.el8, 4.14.0-202410181711.p0.g9a7820e.assembly.stream.el9, 4.15.0-202410181710.p0.gfd77d92.assembly.stream.el8, 4.15.0-202410181710.p0.gfd77d92.assembly.stream.el9
OpenShift Data Foundation (formerly OpenShift Container Storage) - addressed in versions 4.14.13, 4.15.9, 4.16.4, 4.17.1
ose-azure-acr-image-credential-provider (Red Hat package) - addressed in versions 4.15.0-202410181710.p0.g0d799a2.assembly.stream.el8, 4.15.0-202410181710.p0.g0d799a2.assembly.stream.el9
ose-gcp-gcr-image-credential-provider (Red Hat package) - addressed in versions 4.15.0-202410181710.p0.gfc50272.assembly.stream.el8, 4.15.0-202410181710.p0.gfc50272.assembly.stream.el9
kernel-rt (Red Hat package) - addressed in versions 4.18.0-372.127.1.rt7.287.el8_6, 5.14.0-284.90.1.rt14.375.el9_2
podman - addressed in versions 5.2.5-1.fc40, 5.2.5-1.fc41
kernel (Red Hat package) - addressed in versions 5.14.0-284.90.1.el9_2, 5.14.0-427.42.1.el9_4, 5.14.0-427.44.1.el9_4
openstack-ironic-python-agent (Red Hat package) - update to 9.0.1-0.20240913135525.2b2dd8f.el9
openstack-ironic (Red Hat package) - update to 21.0.1-0.20240913135525.114badc.el9
cockpit-podman - update to 84.1-1
External References
Related Security Bulletins
- Denial of service in Podman
- Local denial of service in Buildah
- Local denial of service in CRI-O
- Local denial of service in Container Storage Library
- Fedora 41 update for buildah, containers-common, podman
- Fedora 40 update for podman-tui
- Fedora 41 update for podman-tui
- Fedora EPEL 9 update for podman-tui
- SUSE update for podman
- SUSE update for buildah
- Fedora 40 update for buildah, podman
- UNIX symbolic link following in Red Hat OpenShift Container Platform 4.17
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15 packages
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16 packages
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13 packages
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14 packages
- Red Hat Enterprise Linux 9 update for podman
- Red Hat Enterprise Linux 9 update for podman
- Red Hat Enterprise Linux 9 update for buildah
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17 packages
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- SUSE update for buildah
- Red Hat Enterprise Linux 9 update for buildah
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.3
- Red Hat Enterprise Linux 8 update for the container-tools:rhel8 module
- Multiple vulnerabilities in Red Hat OpenShift Dev Spaces 3.17
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in Migration Toolkit for Containers 1.8
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) 4.17
- SUSE update for buildah
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) 4.16
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.6
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) 4.15
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) 4.14
- openEuler 24.03 LTS SP1 update for podman
- openEuler 24.03 LTS update for podman
- SUSE update for podman
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- SUSE update for podman
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Anolis OS update for container-tools:an8 module
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- openEuler 24.03 LTS SP1 update for buildah
- openEuler 22.03 LTS SP4 update for buildah
- openEuler 24.03 LTS SP3 update for buildah
- openEuler 24.03 LTS SP4 update for skopeo
- openEuler 24.03 LTS SP3 update for skopeo
- openEuler 24.03 LTS SP1 update for skopeo
- openEuler 22.03 LTS SP4 update for skopeo
- openEuler 20.03 LTS SP4 update for skopeo