[GLSA-202407-25] Buildah: Multiple Vulnerabilities

Severity High
Affected Packages 1
Unaffected Packages 1
CVEs 5

Multiple vulnerabilities have been discovered in Buildah, the worst of which could lead to privilege escalation.

Background
Buildah is a tool that facilitates building Open Container Initiative (OCI) container images

Description
Please review the referenced CVE identifiers for details.

Impact
Please review the referenced CVE identifiers for details.

Workaround
There is no known workaround at this time.

Resolution
All Buildah users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose ">=app-containers/buildah-1.35.3"

Package Affected Version
pkg:ebuild/app-containers/buildah?distro=gentoo < 1.35.3
Package Unaffected Version
pkg:ebuild/app-containers/buildah?distro=gentoo >= 1.35.3
Source # ID Name URL
CVE CVE-2024-1753 CVE-2024-1753 https://nvd.nist.gov/vuln/detail/CVE-2024-1753
CVE CVE-2024-23651 CVE-2024-23651 https://nvd.nist.gov/vuln/detail/CVE-2024-23651
CVE CVE-2024-23652 CVE-2024-23652 https://nvd.nist.gov/vuln/detail/CVE-2024-23652
CVE CVE-2024-23653 CVE-2024-23653 https://nvd.nist.gov/vuln/detail/CVE-2024-23653
CVE CVE-2024-24786 CVE-2024-24786 https://nvd.nist.gov/vuln/detail/CVE-2024-24786
Bugzilla 923650 Bugzilla #923650 https://bugs.gentoo.org/show_bug.cgi?id=923650
Bugzilla 927499 Bugzilla #927499 https://bugs.gentoo.org/show_bug.cgi?id=927499
Bugzilla 927502 Bugzilla #927502 https://bugs.gentoo.org/show_bug.cgi?id=927502
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:ebuild/app-containers/buildah?distro=gentoo app-containers buildah < 1.35.3 gentoo
Unaffected pkg:ebuild/app-containers/buildah?distro=gentoo app-containers buildah >= 1.35.3 gentoo
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...