CVE-2024-9676

Red Hat Security Advisory: OpenShift Container Platform 4.14.49 bug fix and security update

Beschreibung

In Podman, Buildah und CRI-O wurde eine Schwachstelle gefunden. Eine Symlink-Traversal-Schwachstelle in der containers/storage-Bibliothek kann dazu führen, dass Podman, Buildah und CRI-O hängen bleiben und zu einem Denial-of-Service-Angriff durch einen OOM-Kill führen, wenn ein bösartiges Image mit einem automatisch zugewiesenen Benutzernamespace (`--userns=auto` in Podman und Buildah) ausgeführt wird. Die containers/storage-Bibliothek liest die Datei /etc/passwd innerhalb des Containers, validiert jedoch nicht ordnungsgemäß, ob es sich um einen Symlink handelt, was dazu genutzt werden kann, die Bibliothek dazu zu bringen, eine beliebige Datei auf dem Host auszulesen.

Metriken

Severity
medium
kein öffentlicher PoC bekannt
6.5
Quelle: cna-v3
69.5 %
Hoch — CVE rangiert über dem Median aller heute bewerteten CVEs (Rang ≥ 36 %).
1.3 %
Moderat — Modell schätzt 1-10 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2025-03-19 20:54 UTC
CWE-22

Weakness-Klassen (CWE)

  • CWE-22Base

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

    The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

    cwe.mitre.org →

Betroffene Betriebssysteme

  • linux

    debian / debian_linux11.0

  • linux

    redhat / enterprise_linux8.0

  • linux

    redhat / enterprise_linux9.0

  • linux

    redhat / enterprise_linux_eus8.8

  • linux

    redhat / enterprise_linux_eus9.0

  • linux

    redhat / enterprise_linux_eus9.2

  • linux

    redhat / enterprise_linux_eus9.4

  • linux

    redhat / enterprise_linux_for_arm_648.0_aarch64

  • linux

    redhat / enterprise_linux_for_arm_649.0_aarch64

  • linux

    redhat / enterprise_linux_for_arm_64_eus8.8_aarch64

  • linux

    redhat / enterprise_linux_for_arm_64_eus9.0_aarch64

  • linux

    redhat / enterprise_linux_for_arm_64_eus9.2_aarch64

  • linux

    redhat / enterprise_linux_for_arm_64_eus9.4_aarch64

  • linux

    redhat / enterprise_linux_for_ibm_z_systems8.0_s390x

  • linux

    redhat / enterprise_linux_for_ibm_z_systems9.0_s390x

  • linux

    redhat / enterprise_linux_for_ibm_z_systems_eus8.8_s390x

  • linux

    redhat / enterprise_linux_for_ibm_z_systems_eus9.0_s390x

  • linux

    redhat / enterprise_linux_for_ibm_z_systems_eus9.2_s390x

  • linux

    redhat / enterprise_linux_for_ibm_z_systems_eus9.4_s390x

  • linux

    redhat / enterprise_linux_for_power_little_endian8.0_ppc64le

  • linux

    redhat / enterprise_linux_for_power_little_endian9.0_ppc64le

  • linux

    redhat / enterprise_linux_for_power_little_endian_eus8.8_ppc64le

  • linux

    redhat / enterprise_linux_for_power_little_endian_eus9.0_ppc64le

  • linux

    redhat / enterprise_linux_for_power_little_endian_eus9.2_ppc64le

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • android

    :linux_kernel::0

  • android

    :linux_kernel:Kernel

  • go

    github.com/containers/buildah1.35.0

  • go

    github.com/containers/buildah1.37.0

  • go

    github.com/containers/buildah1.38.0

  • go

    github.com/containers/buildah

  • go

    golang.org/x/net

  • linuxfoundation

    runc1.1.12

Quellen & Referenzen

Verknüpfte CVEs

IDCVE-2024-9676