跳转到帖子

Alma Linux: CVE-2024-11218: Important: podman security update (Multiple Advisories)

recommended_posts

发布于
  • Members

Alma Linux: CVE-2024-11218: Important: podman security update (Multiple Advisories)

Severity
4
CVSS
(AV:L/AC:M/Au:N/C:P/I:P/A:P)
Published
01/22/2025
Created
02/11/2025
Added
02/10/2025
Modified
02/10/2025

Description

A vulnerability was found in `podman build` and `buildah.` This issue occurs in a container breakout by using --jobs=2 and a race condition when building a malicious Containerfile. SELinux might mitigate it, but even with SELinux on, it still allows the enumeration of files and directories on the host.

Solution(s)

  • alma-upgrade-buildah
  • alma-upgrade-buildah-tests
  • alma-upgrade-podman
  • alma-upgrade-podman-docker
  • alma-upgrade-podman-plugins
  • alma-upgrade-podman-remote
  • alma-upgrade-podman-tests

References

  • https://attackerkb.com/topics/cve-2024-11218
  • CVE - 2024-11218
  • https://errata.almalinux.org/9/ALSA-2025-0922.html
  • https://errata.almalinux.org/9/ALSA-2025-0923.html
  • 查看数 703
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。

游客
回帖…