CVE-2024-9676
15.10.2024, 16:15
A vulnerability was found in Podman, Buildah, and CRI-O. A symlink traversal vulnerability in the containers/storage library can cause Podman, Buildah, and CRI-O to hang and result in a denial of service via OOM kill when running a malicious image using an automatically assigned user namespace (`--userns=auto` in Podman and Buildah). The containers/storage library will read /etc/passwd inside the container, but does not properly validate if that file is a symlink, which can be used to cause the library to read an arbitrary file on the host.
Vendor | Product | Version |
---|---|---|
redhat | openshift_container_platform | 4.12 |
redhat | openshift_container_platform | 4.13 |
redhat | openshift_container_platform | 4.14 |
redhat | openshift_container_platform | 4.15 |
redhat | openshift_container_platform | 4.16 |
redhat | openshift_container_platform | 4.17 |
redhat | openshift_container_platform_for_arm64 | 4.12 |
redhat | openshift_container_platform_for_arm64 | 4.13 |
redhat | openshift_container_platform_for_arm64 | 4.14 |
redhat | openshift_container_platform_for_arm64 | 4.15 |
redhat | openshift_container_platform_for_arm64 | 4.16 |
redhat | openshift_container_platform_for_ibm_z | 4.12 |
redhat | openshift_container_platform_for_ibm_z | 4.13 |
redhat | openshift_container_platform_for_ibm_z | 4.14 |
redhat | openshift_container_platform_for_ibm_z | 4.15 |
redhat | openshift_container_platform_for_ibm_z | 4.16 |
redhat | openshift_container_platform_for_linuxone | 4.12 |
redhat | openshift_container_platform_for_linuxone | 4.13 |
redhat | openshift_container_platform_for_linuxone | 4.14 |
redhat | openshift_container_platform_for_linuxone | 4.15 |
redhat | openshift_container_platform_for_linuxone | 4.16 |
redhat | openshift_container_platform_for_power | 4.12 |
redhat | openshift_container_platform_for_power | 4.13 |
redhat | openshift_container_platform_for_power | 4.14 |
redhat | openshift_container_platform_for_power | 4.15 |
redhat | openshift_container_platform_for_power | 4.16 |
redhat | enterprise_linux | 9.0 |
redhat | enterprise_linux_eus | 9.4 |
redhat | enterprise_linux_for_arm_64 | 9.0_aarch64:_aarch64 |
redhat | enterprise_linux_for_arm_64_eus | 9.4_aarch64:_aarch64 |
redhat | enterprise_linux_for_ibm_z_systems | 9.0_s390x:_s390x |
redhat | enterprise_linux_for_ibm_z_systems_eus | 9.4_s390x:_s390x |
redhat | enterprise_linux_for_power_little_endian | 9.0_ppc64le:_ppc64le |
redhat | enterprise_linux_for_power_little_endian_eus | 9.4_ppc64le:_ppc64le |
redhat | enterprise_linux_server_aus | 9.4 |
redhat | enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions | 9.4_ppc64le:_ppc64le |
𝑥
= Vulnerable software versions

Debian Releases
References