CVE-2024-11218: Red Hat Enterprise Linux 10
High severity, CVSS 8.6. EPSS: 0.4% chance of exploitation in the next 30 days.
A vulnerability was found in `podman build` and `buildah.` This issue occurs in a container breakout by using --jobs=2 and a race condition when building a malicious Containerfile. SELinux might mitigate it, but even with SELinux on, it still allows the enumeration of files and directories on the host.
Affected products
- Red Hat Red Hat Enterprise Linux 10
- Red Hat Red Hat Enterprise Linux 8: before 8100020250124120243.afee755d (fixed in 8100020250124120243.afee755d)
- Red Hat Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support: before 8060020250203202123.3b538bd8 (fixed in 8060020250203202123.3b538bd8)
- Red Hat Red Hat Enterprise Linux 8.6 Telecommunications Update Service: before 8060020250203202123.3b538bd8 (fixed in 8060020250203202123.3b538bd8)
- Red Hat Red Hat Enterprise Linux 8.6 Update Services For SAP Solutions: before 8060020250203202123.3b538bd8 (fixed in 8060020250203202123.3b538bd8)
- Red Hat Red Hat Enterprise Linux 8.8 Extended Update Support: before 8080020250207173112.0f77c1b7 (fixed in 8080020250207173112.0f77c1b7)
- Red Hat Red Hat Enterprise Linux 9: before 4:5.2.2-13.el9_5 (fixed in 4:5.2.2-13.el9_5); before 2:1.37.6-1.el9_5 (fixed in 2:1.37.6-1.el9_5)
- Red Hat Red Hat Enterprise Linux 9.0 Update Services For SAP Solutions: before 2:4.2.0-6.el9_0 (fixed in 2:4.2.0-6.el9_0); before 1:1.26.9-1.el9_0 (fixed in 1:1.26.9-1.el9_0)
- Red Hat Red Hat Enterprise Linux 9.2 Extended Update Support: before 1:1.29.5-1.el9_2 (fixed in 1:1.29.5-1.el9_2); before 2:4.4.1-22.el9_2 (fixed in 2:4.4.1-22.el9_2)
- Red Hat Red Hat Enterprise Linux 9.4 Extended Update Support: before 2:1.33.12-2.el9_4 (fixed in 2:1.33.12-2.el9_4); before 4:4.9.4-17.el9_4 (fixed in 4:4.9.4-17.el9_4)
- Red Hat Red Hat Openshift Container Platform 4
- Red Hat Red Hat Openshift Container Platform 4.12: before 412.86.202503052321-0 (fixed in 412.86.202503052321-0); before 3:4.2.0-13.rhaos4.12.el9 (fixed in 3:4.2.0-13.rhaos4.12.el9)
- Red Hat Red Hat Openshift Container Platform 4.13: before 1:1.29.5-1.rhaos4.13.el8 (fixed in 1:1.29.5-1.rhaos4.13.el8); before 3:4.4.1-16.rhaos4.13.el8 (fixed in 3:4.4.1-16.rhaos4.13.el8); before 413.92.202503112237-0 (fixed in 413.92.202503112237-0)
- Red Hat Red Hat Openshift Container Platform 4.14: before 3:4.4.1-22.rhaos4.14.el8 (fixed in 3:4.4.1-22.rhaos4.14.el8); before 1:1.29.5-1.rhaos4.14.el8 (fixed in 1:1.29.5-1.rhaos4.14.el8); before 414.92.202503100617-0 (fixed in 414.92.202503100617-0)
- Red Hat Red Hat Openshift Container Platform 4.15: before 3:4.4.1-33.rhaos4.15.el8 (fixed in 3:4.4.1-33.rhaos4.15.el8); before 1:1.29.5-1.rhaos4.15.el8 (fixed in 1:1.29.5-1.rhaos4.15.el8); before 415.92.202503060749-0 (fixed in 415.92.202503060749-0)
- Red Hat Red Hat Openshift Container Platform 4.16: before 4:4.9.4-13.rhaos4.16.el8 (fixed in 4:4.9.4-13.rhaos4.16.el8); before 2:1.33.12-1.rhaos4.16.el8 (fixed in 2:1.33.12-1.rhaos4.16.el8); before 416.94.202502180249-0 (fixed in 416.94.202502180249-0)
- Red Hat Red Hat Openshift Container Platform 4.17: before 5:5.2.2-2.rhaos4.17.el8 (fixed in 5:5.2.2-2.rhaos4.17.el8); before 2:1.33.12-1.rhaos4.17.el8 (fixed in 2:1.33.12-1.rhaos4.17.el8); before 417.94.202504080421-0 (fixed in 417.94.202504080421-0)
- Red Hat Red Hat Openshift Container Platform 4.18: before 2:1.33.12-1.rhaos4.18.el9 (fixed in 2:1.33.12-1.rhaos4.18.el9); before 418.94.202504021150-0 (fixed in 418.94.202504021150-0)
Published 2025-01-22. Last modified 2026-08-31.