CVE Database
/

CVE-2024-11218

Back to search

CVE-2024-11218

Published: Jan 22, 2025

Modified: Apr 29, 2026

PUBLISHED

CVSS v3.1

8.6

HIGH

Description

A vulnerability was found in `podman build` and `buildah.` This issue occurs in a container breakout by using --jobs=2 and a race condition when building a malicious Containerfile. SELinux might mitigate it, but even with SELinux on, it still allows the enumeration of files and directories on the host.

VendorProductVersions

Unknown

buildah

affected
0 - < 1.33.12
affected
1.35.0 - < 1.35.5
affected
1.37.0 - < 1.37.6
affected
1.38.0 - < 1.38.1

Red Hat

Red Hat Enterprise Linux 8

unaffected
8100020250124120243.afee755d - < *

Red Hat

Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support

unaffected
8060020250203202123.3b538bd8 - < *

Red Hat

Red Hat Enterprise Linux 8.6 Telecommunications Update Service

unaffected
8060020250203202123.3b538bd8 - < *

Red Hat

Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions

unaffected
8060020250203202123.3b538bd8 - < *

Red Hat

Red Hat Enterprise Linux 8.8 Extended Update Support

unaffected
8080020250207173112.0f77c1b7 - < *

Red Hat

Red Hat Enterprise Linux 9

unaffected
4:5.2.2-13.el9_5 - < *

Red Hat

Red Hat Enterprise Linux 9

unaffected
2:1.37.6-1.el9_5 - < *

Red Hat

Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions

unaffected
2:4.2.0-6.el9_0 - < *

Red Hat

Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions

unaffected
1:1.26.9-1.el9_0 - < *

Red Hat

Red Hat Enterprise Linux 9.2 Extended Update Support

unaffected
1:1.29.5-1.el9_2 - < *

Red Hat

Red Hat Enterprise Linux 9.2 Extended Update Support

unaffected
2:4.4.1-22.el9_2 - < *

Red Hat

Red Hat Enterprise Linux 9.4 Extended Update Support

unaffected
2:1.33.12-2.el9_4 - < *

Red Hat

Red Hat Enterprise Linux 9.4 Extended Update Support

unaffected
4:4.9.4-17.el9_4 - < *

Red Hat

Red Hat OpenShift Container Platform 4.12

unaffected
412.86.202503052321-0 - < *

Red Hat

Red Hat OpenShift Container Platform 4.12

unaffected
3:4.2.0-13.rhaos4.12.el9 - < *

Red Hat

Red Hat OpenShift Container Platform 4.13

unaffected
1:1.29.5-1.rhaos4.13.el8 - < *

Red Hat

Red Hat OpenShift Container Platform 4.13

unaffected
3:4.4.1-16.rhaos4.13.el8 - < *

Red Hat

Red Hat OpenShift Container Platform 4.13

unaffected
413.92.202503112237-0 - < *

Red Hat

Red Hat OpenShift Container Platform 4.14

unaffected
3:4.4.1-22.rhaos4.14.el8 - < *

Red Hat

Red Hat OpenShift Container Platform 4.14

unaffected
1:1.29.5-1.rhaos4.14.el8 - < *

Red Hat

Red Hat OpenShift Container Platform 4.14

unaffected
414.92.202503100617-0 - < *

Red Hat

Red Hat OpenShift Container Platform 4.14

unaffected
1:1.29.5-1.rhaos4.14.el8 - < *

Red Hat

Red Hat OpenShift Container Platform 4.15

unaffected
3:4.4.1-33.rhaos4.15.el8 - < *

Red Hat

Red Hat OpenShift Container Platform 4.15

unaffected
1:1.29.5-1.rhaos4.15.el8 - < *

Red Hat

Red Hat OpenShift Container Platform 4.15

unaffected
415.92.202503060749-0 - < *

Red Hat

Red Hat OpenShift Container Platform 4.15

unaffected
1:1.29.5-1.rhaos4.15.el8 - < *

Red Hat

Red Hat OpenShift Container Platform 4.16

unaffected
4:4.9.4-13.rhaos4.16.el8 - < *

Red Hat

Red Hat OpenShift Container Platform 4.16

unaffected
2:1.33.12-1.rhaos4.16.el8 - < *

Red Hat

Red Hat OpenShift Container Platform 4.16

unaffected
416.94.202502180249-0 - < *

Red Hat

Red Hat OpenShift Container Platform 4.16

unaffected
2:1.33.12-1.rhaos4.16.el8 - < *

Red Hat

Red Hat OpenShift Container Platform 4.17

unaffected
5:5.2.2-2.rhaos4.17.el8 - < *

Red Hat

Red Hat OpenShift Container Platform 4.17

unaffected
2:1.33.12-1.rhaos4.17.el8 - < *

Red Hat

Red Hat OpenShift Container Platform 4.17

unaffected
2:1.33.12-1.rhaos4.17.el8 - < *

Red Hat

Red Hat OpenShift Container Platform 4.17

unaffected
417.94.202504080421-0 - < *

Red Hat

Red Hat OpenShift Container Platform 4.18

unaffected
2:1.33.12-1.rhaos4.18.el9 - < *

Red Hat

Red Hat OpenShift Container Platform 4.18

unaffected
418.94.202504021150-0 - < *

Red Hat

Red Hat Enterprise Linux 10

All versions

Red Hat

Red Hat Enterprise Linux 10

All versions

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Attack Vector

Local

Attack Complexity

Low

Privileges Required

None

User Interaction

Required

Scope

Changed

Confidentiality

High

Integrity

High

Availability

High

References

RHSA-2025:0830
vendor-advisory
x_refsource_REDHAT
RHSA-2025:0878
vendor-advisory
x_refsource_REDHAT
RHSA-2025:0922
vendor-advisory
x_refsource_REDHAT
RHSA-2025:0923
vendor-advisory
x_refsource_REDHAT
RHSA-2025:1186
vendor-advisory
x_refsource_REDHAT
RHSA-2025:1187
vendor-advisory
x_refsource_REDHAT
RHSA-2025:1188
vendor-advisory
x_refsource_REDHAT
RHSA-2025:1189
vendor-advisory
x_refsource_REDHAT
RHSA-2025:1207
vendor-advisory
x_refsource_REDHAT
RHSA-2025:1275
vendor-advisory
x_refsource_REDHAT
RHSA-2025:1295
vendor-advisory
x_refsource_REDHAT
RHSA-2025:1296
vendor-advisory
x_refsource_REDHAT
RHSA-2025:1372
vendor-advisory
x_refsource_REDHAT
RHSA-2025:1453
vendor-advisory
x_refsource_REDHAT
RHSA-2025:1707
vendor-advisory
x_refsource_REDHAT
RHSA-2025:1713
vendor-advisory
x_refsource_REDHAT
RHSA-2025:1908
vendor-advisory
x_refsource_REDHAT
RHSA-2025:1910
vendor-advisory
x_refsource_REDHAT
RHSA-2025:1914
vendor-advisory
x_refsource_REDHAT
RHSA-2025:2441
vendor-advisory
x_refsource_REDHAT
RHSA-2025:2443
vendor-advisory
x_refsource_REDHAT
RHSA-2025:2454
vendor-advisory
x_refsource_REDHAT
RHSA-2025:2456
vendor-advisory
x_refsource_REDHAT
RHSA-2025:2701
vendor-advisory
x_refsource_REDHAT
RHSA-2025:2703
vendor-advisory
x_refsource_REDHAT
RHSA-2025:2710
vendor-advisory
x_refsource_REDHAT
RHSA-2025:2712
vendor-advisory
x_refsource_REDHAT
RHSA-2025:3577
vendor-advisory
x_refsource_REDHAT
RHSA-2025:3798
vendor-advisory
x_refsource_REDHAT
RHBZ#2326231
issue-tracking
x_refsource_REDHAT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now