CVE-2024-9675

Updated: 2025-04-16 02:20:53.801654

Description:

A vulnerability was found in Buildah. Cache mounts do not properly validate that user-specified paths for the cache are within our cache directory, allowing a `RUN` instruction in a Container file to mount an arbitrary directory from the host (read/write) into the container as long as those files can be accessed by the user running Buildah.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0
CVSS Version 3.x HIGH 7.8

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU buildah 1.29.1 7.8 HIGH Released CLSA-2025:1745426658 2025-04-24 04:04:42
AlmaLinux 9.2 ESU kernel 5.14.0 7.8 HIGH Ignored 2024-10-31 10:52:40
CentOS 6 ELS kernel 2.6.32 7.8 HIGH Ignored 2024-10-31 10:52:41
CentOS 7 ELS kernel 3.10.0 7.8 HIGH Ignored 2024-10-31 10:52:40
CentOS 8.4 ELS kernel 4.18.0 7.8 HIGH Ignored 2024-11-05 06:56:49
CentOS 8.5 ELS kernel 4.18.0 7.8 HIGH Ignored 2024-11-05 06:56:51
CentOS Stream 8 ELS kernel 4.18.0 7.8 HIGH Ignored 2024-11-05 06:56:48
CloudLinux 6 ELS kernel 2.6.32 7.8 HIGH Ignored 2024-10-31 10:52:41
CloudLinux 7 ELS kernel 3.10.0 7.8 HIGH Ignored 2024-10-31 10:52:40
Oracle Linux 6 ELS kernel 2.6.32 7.8 HIGH Ignored 2024-10-31 10:52:40