Advisory Database
  • Advisories
  • Dependency Scanning
  1. golang
  2. ›
  3. github.com/containers/podman/v5
  4. ›
  5. CVE-2024-1753

CVE-2024-1753: Podman affected by CVE-2024-1753 container escape at build time

March 28, 2024 (updated November 26, 2024)

What kind of vulnerability is it? Who is impacted?

Users running containers with root privileges allowing a container to run with read/write access to the host system files when selinux is not enabled. With selinux enabled, some read access is allowed.

References

  • access.redhat.com/errata/RHSA-2024:2049
  • access.redhat.com/errata/RHSA-2024:2055
  • access.redhat.com/errata/RHSA-2024:2064
  • access.redhat.com/errata/RHSA-2024:2066
  • access.redhat.com/errata/RHSA-2024:2077
  • access.redhat.com/errata/RHSA-2024:2084
  • access.redhat.com/errata/RHSA-2024:2089
  • access.redhat.com/errata/RHSA-2024:2090
  • access.redhat.com/errata/RHSA-2024:2097
  • access.redhat.com/errata/RHSA-2024:2098
  • access.redhat.com/errata/RHSA-2024:2548
  • access.redhat.com/errata/RHSA-2024:2645
  • access.redhat.com/errata/RHSA-2024:2669
  • access.redhat.com/errata/RHSA-2024:2672
  • access.redhat.com/errata/RHSA-2024:2784
  • access.redhat.com/errata/RHSA-2024:2877
  • access.redhat.com/errata/RHSA-2024:3254
  • access.redhat.com/security/cve/CVE-2024-1753
  • bugzilla.redhat.com/show_bug.cgi?id=2265513
  • github.com/advisories/GHSA-874v-pj72-92f3
  • github.com/containers/buildah/security/advisories/GHSA-pmf3-c36m-g5cf
  • github.com/containers/podman
  • github.com/containers/podman/security/advisories/GHSA-874v-pj72-92f3
  • lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FCRZVUDOFM5CPREQKBEU2VK2QK62PSBP
  • lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KOYMVMQ7RWMDTSKQTBO734BE3WQPI2AJ
  • lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZVBSVZGVABPYIHK5HZM472NPGWMI7WXH
  • nvd.nist.gov/vuln/detail/CVE-2024-1753
  • pkg.go.dev/vuln/GO-2024-2658

Code Behaviors & Features

Detect and mitigate CVE-2024-1753 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 5.0.1

Fixed versions

  • 5.0.1

Solution

Upgrade to version 5.0.1 or above.

Impact 8.6 HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-269: Improper Privilege Management
  • CWE-59: Improper Link Resolution Before File Access ('Link Following')

Source file

go/github.com/containers/podman/v5/CVE-2024-1753.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:15:14 +0000.