Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2024-1753 Details

UNDERGOING ENRICHMENT


The CVE is currently being enriched by the Volerion team. The enrichment process results in the association of reference link tags, CVSS, and CPE applicability statement data.

Description

A flaw was found in Buildah (and subsequently Podman Build) which allows containers to mount arbitrary locations on the host filesystem into build containers. A malicious Containerfile can use a dummy image with a symbolic link to the root filesystem as a mount source and cause the mount operation to mount the host root filesystem inside the RUN step. The commands inside the RUN step will then have read-write access to the host filesystem, allowing for full container escape at build time.

Metrics

CVSS 3.x Severity and Vector Strings:

NDDVolerionCVSS-B:…Vector:This vulnerability is currently being analyzed.

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
https://access.redhat.com/errata/RHSA-2024:2049 CVE
https://access.redhat.com/errata/RHSA-2024:2055 CVE
https://access.redhat.com/errata/RHSA-2024:2064 CVE
https://access.redhat.com/errata/RHSA-2024:2066 CVE
https://access.redhat.com/errata/RHSA-2024:2077 CVE

see all 46 references

Weakness Enumeration

CWE-IDCWE NameSource
CWE-59Improper Link Resolution Before File Access ('Link Following')[email protected]

Affected Products

This vulnerability is currently being analyzed

Change History

28 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2024-1753
NVD Published Date:
Mar 18, 2024
NVD Last Modified:
Sep 25, 2026
Source:
[email protected]
CVE-2024-1753 Details - Not Deferred