CVE-2024-9676
MEDIUM EPSS 67.9%
Published Oct 15, 20241y ago · Modified Jun 17, 20261w ago
6.5 CVSS 3.1
Published Oct 15, 2024 1y ago
Last Modified Jun 17, 2026 1w ago
Description
A vulnerability was found in Podman, Buildah, and CRI-O. A symlink traversal vulnerability in the containers/storage library can cause Podman, Buildah, and CRI-O to hang and result in a denial of service via OOM kill when running a malicious image using an automatically assigned user namespace (`--userns=auto` in Podman and Buildah). The containers/storage library will read /etc/passwd inside the container, but does not properly validate if that file is a symlink, which can be used to cause the library to read an arbitrary file on the host.
CVSS Details
Base Score
Exploitability
Impact
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Attack Vector Network
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High
Threat Intelligence
EPSS Exploit Probability
67.9% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available
Weaknesses 1
CWE-22 Path Traversal Resource Mgmt
Affected Products 36
| Vendor | Product | Version | Range |
|---|---|---|---|
| redhat | openshift_container_platform | 4.12 | any |
| redhat | openshift_container_platform | 4.13 | any |
| redhat | openshift_container_platform | 4.14 | any |
| redhat | openshift_container_platform | 4.15 | any |
| redhat | openshift_container_platform | 4.16 | any |
| redhat | openshift_container_platform | 4.17 | any |
| redhat | openshift_container_platform_for_arm64 | 4.12 | any |
| redhat | openshift_container_platform_for_arm64 | 4.13 | any |
| redhat | openshift_container_platform_for_arm64 | 4.14 | any |
| redhat | openshift_container_platform_for_arm64 | 4.15 | any |
| redhat | openshift_container_platform_for_arm64 | 4.16 | any |
| redhat | openshift_container_platform_for_ibm_z | 4.12 | any |
| redhat | openshift_container_platform_for_ibm_z | 4.13 | any |
| redhat | openshift_container_platform_for_ibm_z | 4.14 | any |
| redhat | openshift_container_platform_for_ibm_z | 4.15 | any |
| redhat | openshift_container_platform_for_ibm_z | 4.16 | any |
| redhat | openshift_container_platform_for_linuxone | 4.12 | any |
| redhat | openshift_container_platform_for_linuxone | 4.13 | any |
| redhat | openshift_container_platform_for_linuxone | 4.14 | any |
| redhat | openshift_container_platform_for_linuxone | 4.15 | any |
| redhat | openshift_container_platform_for_linuxone | 4.16 | any |
| redhat | openshift_container_platform_for_power | 4.12 | any |
| redhat | openshift_container_platform_for_power | 4.13 | any |
| redhat | openshift_container_platform_for_power | 4.14 | any |
| redhat | openshift_container_platform_for_power | 4.15 | any |
| redhat | openshift_container_platform_for_power | 4.16 | any |
| redhat | enterprise_linux | 9.0 | any |
| redhat | enterprise_linux_eus | 9.4 | any |
| redhat | enterprise_linux_for_arm_64 | 9.0_aarch64 | any |
| redhat | enterprise_linux_for_arm_64_eus | 9.4_aarch64 | any |
| redhat | enterprise_linux_for_ibm_z_systems | 9.0_s390x | any |
| redhat | enterprise_linux_for_ibm_z_systems_eus | 9.4_s390x | any |
| redhat | enterprise_linux_for_power_little_endian | 9.0_ppc64le | any |
| redhat | enterprise_linux_for_power_little_endian_eus | 9.4_ppc64le | any |
| redhat | enterprise_linux_server_aus | 9.4 | any |
| redhat | enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions | 9.4_ppc64le | any |
References 21
- access.redhat.com https://access.redhat.com/errata/RHSA-2024:10289
- access.redhat.com https://access.redhat.com/errata/RHSA-2024:8418
- access.redhat.com https://access.redhat.com/errata/RHSA-2024:8428
- access.redhat.com https://access.redhat.com/errata/RHSA-2024:8437
- access.redhat.com https://access.redhat.com/errata/RHSA-2024:8686
- access.redhat.com https://access.redhat.com/errata/RHSA-2024:8690
- access.redhat.com https://access.redhat.com/errata/RHSA-2024:8694
- access.redhat.com https://access.redhat.com/errata/RHSA-2024:8700
- access.redhat.com https://access.redhat.com/errata/RHSA-2024:8984
- access.redhat.com https://access.redhat.com/errata/RHSA-2024:9051
- access.redhat.com https://access.redhat.com/errata/RHSA-2024:9454
- access.redhat.com https://access.redhat.com/errata/RHSA-2024:9459
- access.redhat.com https://access.redhat.com/errata/RHSA-2024:9926
- access.redhat.com https://access.redhat.com/errata/RHSA-2025:0876
- access.redhat.com https://access.redhat.com/errata/RHSA-2025:2454
- access.redhat.com https://access.redhat.com/errata/RHSA-2025:2710
- access.redhat.com https://access.redhat.com/errata/RHSA-2025:3301
- access.redhat.com https://access.redhat.com/security/cve/CVE-2024-9676
- bugzilla.redhat.com https://bugzilla.redhat.com/show_bug.cgi?id=2317467
- github.com https://github.com/advisories/GHSA-wq2p-5pc6-wpgf
- github.com https://github.com/containers/storage/commit/935c58f4b3e364a9c9d33ed06476a831e6ad5679
Remediation
No remediation data recorded yet
Check vendor advisories and the NVD entry for patch availability.