CVE-2024-11218 Details
Description
A vulnerability was found in `podman build` and `buildah.` This issue occurs in a container breakout by using --jobs=2 and a race condition when building a malicious Containerfile. SELinux might mitigate it, but even with SELinux on, it still allows the enumeration of files and directories on the host.
A vulnerability allowing container breakout has been identified in Red Hat Podman and Buildah. This issue arises when using the '--jobs=2' option, creating a race condition while building a malicious Containerfile. Although SELinux may provide some mitigation, it still permits the enumeration of files and directories on the host.
Users can upgrade to the latest versions of Podman or Buildah, which include the necessary fixes. Instructions for applying these updates are available on the Red Hat Customer Portal.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jan 22, 2025CISA-ADP
Assessed Jan 22, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-269 | Improper Privilege Management | [email protected] |
Affected Products
Change History
33 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 31, 2026 | CVE Modified | [email protected] |
| Jun 29, 2026 | CVE Modified | [email protected] |
| Jun 25, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 2, 2025 | CVE Modified | [email protected] |
| Apr 16, 2025 | CVE Modified | [email protected] |
| Apr 10, 2025 | CVE Modified | [email protected] |
| Mar 20, 2025 | CVE Modified | [email protected] |
| Mar 20, 2025 | CVE Modified | [email protected] |
| Mar 19, 2025 | CVE Modified | [email protected] |
| Mar 19, 2025 | CVE Modified | [email protected] |
| Mar 13, 2025 | CVE Modified | [email protected] |
| Mar 13, 2025 | CVE Modified | [email protected] |
| Mar 13, 2025 | CVE Modified | [email protected] |
| Mar 13, 2025 | CVE Modified | [email protected] |
| Mar 5, 2025 | CVE Modified | [email protected] |
| Mar 5, 2025 | CVE Modified | [email protected] |
| Mar 4, 2025 | CVE Modified | [email protected] |
| Feb 27, 2025 | CVE Modified | [email protected] |
| Feb 27, 2025 | CVE Modified | [email protected] |
| Feb 20, 2025 | CVE Modified | [email protected] |
| Feb 13, 2025 | CVE Modified | [email protected] |
| Feb 11, 2025 | CVE Modified | [email protected] |
| Feb 11, 2025 | CVE Modified | [email protected] |
| Feb 10, 2025 | CVE Modified | [email protected] |
| Feb 10, 2025 | CVE Modified | [email protected] |
| Feb 10, 2025 | CVE Modified | [email protected] |
| Feb 10, 2025 | CVE Modified | [email protected] |
| Feb 6, 2025 | CVE Modified | [email protected] |
| Feb 4, 2025 | CVE Modified | [email protected] |
| Feb 4, 2025 | CVE Modified | [email protected] |
| Jan 22, 2025 | New CVE Received | [email protected] |
Volerion