Attacker Value
Unknown
(0 users assessed)
Exploitability
Unknown
(0 users assessed)
User Interaction
None
Privileges Required
Low
Attack Vector
Network
0

CVE-2024-9676

Disclosure Date: October 15, 2024
Add MITRE ATT&CK tactics and techniques that apply to this CVE.

Description

A vulnerability was found in Podman, Buildah, and CRI-O. A symlink traversal vulnerability in the containers/storage library can cause Podman, Buildah, and CRI-O to hang and result in a denial of service via OOM kill when running a malicious image using an automatically assigned user namespace (--userns=auto in Podman and Buildah). The containers/storage library will read /etc/passwd inside the container, but does not properly validate if that file is a symlink, which can be used to cause the library to read an arbitrary file on the host.

Add Assessment

No one has assessed this topic. Be the first to add your voice to the community.

CVSS V3 Severity and Metrics
Base Score:
6.5 Medium
Impact Score:
3.6
Exploitability Score:
2.8
Vector:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector (AV):
Network
Attack Complexity (AC):
Low
Privileges Required (PR):
Low
User Interaction (UI):
None
Scope (S):
Unchanged
Confidentiality (C):
None
Integrity (I):
None
Availability (A):
High

General Information

Vendors

  • Red Hat

Products

  • Red Hat Enterprise Linux 9,
  • Red Hat OpenShift Container Platform 4.12,
  • Red Hat OpenShift Container Platform 4.13,
  • Red Hat OpenShift Container Platform 4.14,
  • Red Hat OpenShift Container Platform 4.15,
  • Red Hat OpenShift Container Platform 4.16,
  • Red Hat OpenShift Container Platform 4.17,
  • OpenShift Developer Tools and Services,
  • Red Hat Enterprise Linux 8,
  • Red Hat OpenShift Container Platform 4,
  • Red Hat Quay 3
Technical Analysis