CVE-2024-9676
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Oct 15, 2024
Updated: Mar 20, 2025
CWE ID 22
Summary
CVE-2024-9676 is a newly discovered vulnerability affecting Podman, Buildah, and CRI-O containers. This issue involves a symlink traversal flaw in the containers/storage library, which can trigger a denial of service attack. When running a malicious image with an automatically assigned user namespace, the library reads /etc/passwd inside the container without validating if it's a symlink. An attacker can exploit this vulnerability to cause the library to read an arbitrary file on the host system, leading to a hang and potential out-of-memory kill.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Red Hat Openshift Container Platform
- Red Hat Enterprise Linux
- Redhat Enterprise Linux For Ibm Z Systems
Affected Vendors
- Red Hat