CVE-2024-11218
CVSS 3.1 Score 8.6 of 10 (high)
Details
Published Jan 22, 2025
CWE ID 269
Summary
CVE-2024-11218 is a newly identified vulnerability affecting `podman build` and `buildah`. The issue arises when building a malicious Containerfile using the --jobs=2 flag, which results in a container breakout and a race condition. Although SELinux may offer some mitigation, it does not prevent the enumeration of files and directories on the host system. This vulnerability poses a potential security risk to container environments.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.