CVE-2024-9676

EUVD-2024-50452
A vulnerability was found in Podman, Buildah, and CRI-O. A symlink traversal vulnerability in the containers/storage library can cause Podman, Buildah, and CRI-O to hang and result in a denial of service via OOM kill when running a malicious image using an automatically assigned user namespace (`--userns=auto` in Podman and Buildah). The containers/storage library will read /etc/passwd inside the container, but does not properly validate if that file is a symlink, which can be used to cause the library to read an arbitrary file on the host.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 81%
Affected Products (NVD)
VendorProductVersion
redhatopenshift_container_platform
4.12
redhatopenshift_container_platform
4.13
redhatopenshift_container_platform
4.14
redhatopenshift_container_platform
4.15
redhatopenshift_container_platform
4.16
redhatopenshift_container_platform
4.17
redhatopenshift_container_platform_for_arm64
4.12
redhatopenshift_container_platform_for_arm64
4.13
redhatopenshift_container_platform_for_arm64
4.14
redhatopenshift_container_platform_for_arm64
4.15
redhatopenshift_container_platform_for_arm64
4.16
redhatopenshift_container_platform_for_ibm_z
4.12
redhatopenshift_container_platform_for_ibm_z
4.13
redhatopenshift_container_platform_for_ibm_z
4.14
redhatopenshift_container_platform_for_ibm_z
4.15
redhatopenshift_container_platform_for_ibm_z
4.16
redhatopenshift_container_platform_for_linuxone
4.12
redhatopenshift_container_platform_for_linuxone
4.13
redhatopenshift_container_platform_for_linuxone
4.14
redhatopenshift_container_platform_for_linuxone
4.15
redhatopenshift_container_platform_for_linuxone
4.16
redhatopenshift_container_platform_for_power
4.12
redhatopenshift_container_platform_for_power
4.13
redhatopenshift_container_platform_for_power
4.14
redhatopenshift_container_platform_for_power
4.15
redhatopenshift_container_platform_for_power
4.16
redhatenterprise_linux
9.0
redhatenterprise_linux_eus
9.4
redhatenterprise_linux_for_arm_64
9.0_aarch64:_aarch64
redhatenterprise_linux_for_arm_64_eus
9.4_aarch64:_aarch64
redhatenterprise_linux_for_ibm_z_systems
9.0_s390x:_s390x
redhatenterprise_linux_for_ibm_z_systems_eus
9.4_s390x:_s390x
redhatenterprise_linux_for_power_little_endian
9.0_ppc64le:_ppc64le
redhatenterprise_linux_for_power_little_endian_eus
9.4_ppc64le:_ppc64le
redhatenterprise_linux_server_aus
9.4
redhatenterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions
9.4_ppc64le:_ppc64le
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
golang-github-containers-storage
bookworm
no-dsa
bullseye
postponed
forky
1.61.0+ds1-6
fixed
sid
1.61.0+ds1-6
fixed
trixie
1.57.2+ds1-1
fixed
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
buildah
suse enterprise sap 15 SP5
1.35.4-150500.3.19.1
fixed
suse enterprise sap 15 SP6
1.35.4-150500.3.19.1
fixed
suse enterprise sap 15 SP7
1.35.4-150500.3.19.1
fixed
suse enterprise server 15 SP3
1.35.4-150300.8.28.3
fixed
suse enterprise server 15 SP4
1.35.4-150400.3.33.1
fixed
suse enterprise server 15 SP5
1.35.4-150500.3.19.1
fixed
suse enterprise server 15 SP6
1.35.4-150500.3.19.1
fixed
suse enterprise server 15 SP7
1.35.4-150500.3.19.1
fixed
podman
suse enterprise sap 15 SP5
4.9.5-150500.3.28.1
fixed
suse enterprise sap 15 SP6
4.9.5-150500.3.28.1
fixed
suse enterprise sap 15 SP7
4.9.5-150500.3.28.1
fixed
suse enterprise server 15 SP3
4.9.5-150300.9.43.1
fixed
suse enterprise server 15 SP4
4.9.5-150400.4.35.1
fixed
suse enterprise server 15 SP5
4.9.5-150500.3.28.1
fixed
suse enterprise server 15 SP6
4.9.5-150500.3.28.1
fixed
suse enterprise server 15 SP7
4.9.5-150500.3.28.1
fixed
podman-docker
suse enterprise sap 15 SP5
4.9.5-150500.3.28.1
fixed
suse enterprise sap 15 SP6
4.9.5-150500.3.28.1
fixed
suse enterprise sap 15 SP7
4.9.5-150500.3.28.1
fixed
suse enterprise server 15 SP4
4.9.5-150400.4.35.1
fixed
suse enterprise server 15 SP5
4.9.5-150500.3.28.1
fixed
suse enterprise server 15 SP6
4.9.5-150500.3.28.1
fixed
suse enterprise server 15 SP7
4.9.5-150500.3.28.1
fixed
podman-remote
suse enterprise sap 15 SP5
4.9.5-150500.3.28.1
fixed
suse enterprise sap 15 SP6
4.9.5-150500.3.28.1
fixed
suse enterprise sap 15 SP7
4.9.5-150500.3.28.1
fixed
suse enterprise server 15 SP3
4.9.5-150300.9.43.1
fixed
suse enterprise server 15 SP4
4.9.5-150400.4.35.1
fixed
suse enterprise server 15 SP5
4.9.5-150500.3.28.1
fixed
suse enterprise server 15 SP6
4.9.5-150500.3.28.1
fixed
suse enterprise server 15 SP7
4.9.5-150500.3.28.1
fixed
podmansh
suse enterprise sap 15 SP5
4.9.5-150500.3.28.1
fixed
suse enterprise sap 15 SP6
4.9.5-150500.3.28.1
fixed
suse enterprise sap 15 SP7
4.9.5-150500.3.28.1
fixed
suse enterprise server 15 SP5
4.9.5-150500.3.28.1
fixed
suse enterprise server 15 SP6
4.9.5-150500.3.28.1
fixed
suse enterprise server 15 SP7
4.9.5-150500.3.28.1
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
buildah
RHEL 9
2:1.37.5-1.el9_5
fixed
buildah-tests
RHEL 9
2:1.37.5-1.el9_5
fixed
podman
RHEL 9
4:5.2.2-9.el9_5
fixed
podman-docker
RHEL 9
4:5.2.2-9.el9_5
fixed
podman-plugins
RHEL 9
4:5.2.2-9.el9_5
fixed
podman-remote
RHEL 9
4:5.2.2-9.el9_5
fixed
podman-tests
RHEL 9
4:5.2.2-9.el9_5
fixed