[ALPINE:CVE-2024-1753] podman, buildah vulnerability
Severity
High
Fixed Packages
32
CVEs
1
[From CVE-2024-1753] A flaw was found in Buildah (and subsequently Podman Build) which allows containers to mount arbitrary locations on the host filesystem into build containers. A malicious Containerfile can use a dummy image with a symbolic link to the root filesystem as a mount source and cause the mount operation to mount the host root filesystem inside the RUN step. The commands inside the RUN step will then have read-write access to the host filesystem, allowing for full container escape at build time.
- ID
- ALPINE:CVE-2024-1753
- Severity
- high
- Severity from
- CVE-2024-1753
- URL
- https://security.alpinelinux.org/vuln/CVE-2024-1753
- Published
-
2024-03-18T15:15:41
(6 months ago) - Modified
-
2024-03-18T15:15:41
(6 months ago) - Rights
- Alpine Linux Security Team
- Other Advisories
-
- ALSA-2024:2055
- ALSA-2024:2084
- ALSA-2024:2098
- ALSA-2024:2548
- ALSA-2024:3254
- ELSA-2024-2055
- ELSA-2024-2084
- ELSA-2024-2098
- ELSA-2024-2548
- ELSA-2024-3254
- FEDORA-2024-8409b5fa8e
- FEDORA-2024-a267e93f8c
- FEDORA-2024-dd32f390b3
- GLSA-202407-12
- GLSA-202407-25
- GO-2024-2658
- RHSA-2024:2055
- RHSA-2024:2084
- RHSA-2024:2098
- RHSA-2024:2548
- RHSA-2024:3254
- RLSA-2024:2548
- SUSE-SU-2024:1058-1
- SUSE-SU-2024:1059-1
- SUSE-SU-2024:1142-1
- SUSE-SU-2024:1143-1
- SUSE-SU-2024:1144-1
- SUSE-SU-2024:1145-1
- SUSE-SU-2024:1146-1
- SUSE-SU-2024:3120-1
- SUSE-SU-2024:3151-1
- SUSE-SU-2024:3186-1
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Fixed | pkg:apk/alpine/podman?arch=x86_64&distro=alpine-edge | alpine | podman | = 4.9.4-r0 | alpine-edge | x86_64 | |
Fixed | pkg:apk/alpine/podman?arch=x86_64&distro=alpine-3.20 | alpine | podman | = 4.9.4-r0 | alpine-3.20 | x86_64 | |
Fixed | pkg:apk/alpine/podman?arch=x86&distro=alpine-edge | alpine | podman | = 4.9.4-r0 | alpine-edge | x86 | |
Fixed | pkg:apk/alpine/podman?arch=x86&distro=alpine-3.20 | alpine | podman | = 4.9.4-r0 | alpine-3.20 | x86 | |
Fixed | pkg:apk/alpine/podman?arch=s390x&distro=alpine-edge | alpine | podman | = 4.9.4-r0 | alpine-edge | s390x | |
Fixed | pkg:apk/alpine/podman?arch=s390x&distro=alpine-3.20 | alpine | podman | = 4.9.4-r0 | alpine-3.20 | s390x | |
Fixed | pkg:apk/alpine/podman?arch=riscv64&distro=alpine-edge | alpine | podman | = 4.9.4-r0 | alpine-edge | riscv64 | |
Fixed | pkg:apk/alpine/podman?arch=riscv64&distro=alpine-3.20 | alpine | podman | = 4.9.4-r0 | alpine-3.20 | riscv64 | |
Fixed | pkg:apk/alpine/podman?arch=ppc64le&distro=alpine-edge | alpine | podman | = 4.9.4-r0 | alpine-edge | ppc64le | |
Fixed | pkg:apk/alpine/podman?arch=ppc64le&distro=alpine-3.20 | alpine | podman | = 4.9.4-r0 | alpine-3.20 | ppc64le | |
Fixed | pkg:apk/alpine/podman?arch=armv7&distro=alpine-edge | alpine | podman | = 4.9.4-r0 | alpine-edge | armv7 | |
Fixed | pkg:apk/alpine/podman?arch=armv7&distro=alpine-3.20 | alpine | podman | = 4.9.4-r0 | alpine-3.20 | armv7 | |
Fixed | pkg:apk/alpine/podman?arch=armhf&distro=alpine-edge | alpine | podman | = 4.9.4-r0 | alpine-edge | armhf | |
Fixed | pkg:apk/alpine/podman?arch=armhf&distro=alpine-3.20 | alpine | podman | = 4.9.4-r0 | alpine-3.20 | armhf | |
Fixed | pkg:apk/alpine/podman?arch=aarch64&distro=alpine-edge | alpine | podman | = 4.9.4-r0 | alpine-edge | aarch64 | |
Fixed | pkg:apk/alpine/podman?arch=aarch64&distro=alpine-3.20 | alpine | podman | = 4.9.4-r0 | alpine-3.20 | aarch64 | |
Fixed | pkg:apk/alpine/buildah?arch=x86_64&distro=alpine-edge | alpine | buildah | = 1.35.4-r0 | alpine-edge | x86_64 | |
Fixed | pkg:apk/alpine/buildah?arch=x86_64&distro=alpine-3.20 | alpine | buildah | = 1.35.4-r0 | alpine-3.20 | x86_64 | |
Fixed | pkg:apk/alpine/buildah?arch=x86&distro=alpine-edge | alpine | buildah | = 1.35.4-r0 | alpine-edge | x86 | |
Fixed | pkg:apk/alpine/buildah?arch=x86&distro=alpine-3.20 | alpine | buildah | = 1.35.4-r0 | alpine-3.20 | x86 | |
Fixed | pkg:apk/alpine/buildah?arch=s390x&distro=alpine-edge | alpine | buildah | = 1.35.4-r0 | alpine-edge | s390x | |
Fixed | pkg:apk/alpine/buildah?arch=s390x&distro=alpine-3.20 | alpine | buildah | = 1.35.4-r0 | alpine-3.20 | s390x | |
Fixed | pkg:apk/alpine/buildah?arch=riscv64&distro=alpine-edge | alpine | buildah | = 1.35.4-r0 | alpine-edge | riscv64 | |
Fixed | pkg:apk/alpine/buildah?arch=riscv64&distro=alpine-3.20 | alpine | buildah | = 1.35.4-r0 | alpine-3.20 | riscv64 | |
Fixed | pkg:apk/alpine/buildah?arch=ppc64le&distro=alpine-edge | alpine | buildah | = 1.35.4-r0 | alpine-edge | ppc64le | |
Fixed | pkg:apk/alpine/buildah?arch=ppc64le&distro=alpine-3.20 | alpine | buildah | = 1.35.4-r0 | alpine-3.20 | ppc64le | |
Fixed | pkg:apk/alpine/buildah?arch=armv7&distro=alpine-edge | alpine | buildah | = 1.35.4-r0 | alpine-edge | armv7 | |
Fixed | pkg:apk/alpine/buildah?arch=armv7&distro=alpine-3.20 | alpine | buildah | = 1.35.4-r0 | alpine-3.20 | armv7 | |
Fixed | pkg:apk/alpine/buildah?arch=armhf&distro=alpine-edge | alpine | buildah | = 1.35.4-r0 | alpine-edge | armhf | |
Fixed | pkg:apk/alpine/buildah?arch=armhf&distro=alpine-3.20 | alpine | buildah | = 1.35.4-r0 | alpine-3.20 | armhf | |
Fixed | pkg:apk/alpine/buildah?arch=aarch64&distro=alpine-edge | alpine | buildah | = 1.35.4-r0 | alpine-edge | aarch64 | |
Fixed | pkg:apk/alpine/buildah?arch=aarch64&distro=alpine-3.20 | alpine | buildah | = 1.35.4-r0 | alpine-3.20 | aarch64 |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |