CVE-2024-9341
HIGH EPSS 58.1%
Published Oct 1, 20241y ago · Modified Jun 17, 20261w ago
8.2 CVSS 3.1
Published Oct 1, 2024 1y ago
Last Modified Jun 17, 2026 1w ago
Description
A flaw was found in Go. When FIPS mode is enabled on a system, container runtimes may incorrectly handle certain file paths due to improper validation in the containers/common Go library. This flaw allows an attacker to exploit symbolic links and trick the system into mounting sensitive host directories inside a container. This issue also allows attackers to access critical host files, bypassing the intended isolation between containers and the host system.
CVSS Details
Base Score
Exploitability
Impact
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction Required
Scope Changed
Confidentiality High
Integrity Low
Availability None
Threat Intelligence
EPSS Exploit Probability
58.1% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available
Weaknesses 1
CWE-59
Affected Products 9
| Vendor | Product | Version | Range |
|---|---|---|---|
| containers | common | * | any |
| redhat | openshift_container_platform | 4.12 | any |
| redhat | openshift_container_platform | 4.13 | any |
| redhat | openshift_container_platform | 4.14 | any |
| redhat | openshift_container_platform | 4.15 | any |
| redhat | openshift_container_platform | 4.16 | any |
| redhat | openshift_container_platform | 4.17 | any |
| redhat | enterprise_linux | 8.0 | any |
| redhat | enterprise_linux | 9.0 | any |
References 17
- access.redhat.com https://access.redhat.com/errata/RHSA-2024:10147
- access.redhat.com https://access.redhat.com/errata/RHSA-2024:10818
- access.redhat.com https://access.redhat.com/errata/RHSA-2024:7925
- access.redhat.com https://access.redhat.com/errata/RHSA-2024:8039
- access.redhat.com https://access.redhat.com/errata/RHSA-2024:8112
- access.redhat.com https://access.redhat.com/errata/RHSA-2024:8238
- access.redhat.com https://access.redhat.com/errata/RHSA-2024:8263
- access.redhat.com https://access.redhat.com/errata/RHSA-2024:8428
- access.redhat.com https://access.redhat.com/errata/RHSA-2024:8690
- access.redhat.com https://access.redhat.com/errata/RHSA-2024:8694
- access.redhat.com https://access.redhat.com/errata/RHSA-2024:8846
- access.redhat.com https://access.redhat.com/errata/RHSA-2024:9454
- access.redhat.com https://access.redhat.com/errata/RHSA-2024:9459
- access.redhat.com https://access.redhat.com/security/cve/CVE-2024-9341
- bugzilla.redhat.com https://bugzilla.redhat.com/show_bug.cgi?id=2315691
- github.com https://github.com/containers/common/blob/384f77532f67afc8a73d8e0c4adb0d195df57714/pkg/subscriptions/subscriptions.go#L169
- github.com https://github.com/containers/common/blob/384f77532f67afc8a73d8e0c4adb0d195df57714/pkg/subscriptions/subscriptions.go#L349
Remediation
No remediation data recorded yet
Check vendor advisories and the NVD entry for patch availability.