Skip to content
VulniPulse
Highest advisory severityHigh 1 vendor · 1 advisory

CVE-2024-1753

CVE-2024-1753: 1 tracked advisory record across Red Hat. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Red Hat

1 advisory
  • Advisory severityHigh8.6

    High [CVE-2024-1753] Buildah: buildah: container escape via improper bind mount validation

    CVE-2024-1753Source published Source updated

    A flaw was found in Buildah (and subsequently Podman Build) which allows containers to mount arbitrary locations on the host filesystem into build containers. A malicious Containerfile can use a dummy image with a symbolic link to the root filesystem as a mount source and cause the mount operation to mount the host root filesystem inside the RUN step. The commands inside the RUN step will then have read-write access to the host filesystem, allowing for full container escape at build time. Red Hat has rated this vulnerability as Important rather than Critical because successful exploitation requires user interaction to process a maliciously crafted Containerfile. Additionally, default security hardening in Red Hat Enterprise Linux—specifically SELinux running in Enforcing mode—prevents…

    Affected products in this advisory
    • Red Hat Enterprise Linux 8.6 Extended Update Support
    • Red Hat Enterprise Linux 8.8 Extended Update Support
    • Red Hat Enterprise Linux 9.0 Extended Update Support
    • Red Hat Enterprise Linux 9.2 Extended Update Support

    8 more entries in the full advisory.

    Source-reported affected versions
    Affected-version details not available in this record.
    Source-reported fixed versions
    • container-tools:4.0-8090020240413110917.d7b6f4b7
    • container-tools:rhel8-8090020240417184044.e7857ab1
    • container-tools:rhel8-8100020240419145834.afee755d
    • container-tools:rhel8-8060020240422155330.3b538bd8

    30 more entries in the full advisory.

    Mitigation guidance
    • When SELinux is enabled, the container is restricted to limited read-only access.

Android app · Google Play

Monitor future Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery