Name | CVE-2024-11218 |
Description | A vulnerability was found in `podman build` and `buildah.` This issue occurs in a container breakout by using --jobs=2 and a race condition when building a malicious Containerfile. SELinux might mitigate it, but even with SELinux on, it still allows the enumeration of files and directories on the host. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|---|---|---|
golang-github-containers-buildah (PTS) | bullseye | 1.19.6+dfsg1-1 | vulnerable |
bookworm | 1.28.2+ds1-3+deb12u1 | vulnerable | |
sid, trixie | 1.39.3+ds1-1 | fixed |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
golang-github-containers-buildah | source | (unstable) | 1.38.1+ds1-1 |
[bookworm] - golang-github-containers-buildah <no-dsa> (Minor issue)
[bullseye] - golang-github-containers-buildah <no-dsa> (Minor issue)
https://github.com/advisories/GHSA-5vpc-35f4-r8w6