CVE-2024-1753: Red Hat Enterprise Linux 7

High severity, CVSS 8.6. EPSS: 0.5% chance of exploitation in the next 30 days.

A flaw was found in Buildah (and subsequently Podman Build) which allows containers to mount arbitrary locations on the host filesystem into build containers. A malicious Containerfile can use a dummy image with a symbolic link to the root filesystem as a mount source and cause the mount operation to mount the host root filesystem inside the RUN step. The commands inside the RUN step will then have read-write access to the host filesystem, allowing for full container escape at build time.

Affected products

  • Red Hat Red Hat Enterprise Linux 7
  • Red Hat Red Hat Enterprise Linux 8: before 8090020240413110917.d7b6f4b7 (fixed in 8090020240413110917.d7b6f4b7); before 8090020240417184044.e7857ab1 (fixed in 8090020240417184044.e7857ab1); before 8100020240419145834.afee755d (fixed in 8100020240419145834.afee755d)
  • Red Hat Red Hat Enterprise Linux 8.6 Extended Update Support: before 8060020240422155330.3b538bd8 (fixed in 8060020240422155330.3b538bd8); before 8060020240419071711.2e213529 (fixed in 8060020240419071711.2e213529)
  • Red Hat Red Hat Enterprise Linux 8.8 Extended Update Support: before 8080020240422101606.0f77c1b7 (fixed in 8080020240422101606.0f77c1b7)
  • Red Hat Red Hat Enterprise Linux 9: before 1:1.31.5-1.el9_3 (fixed in 1:1.31.5-1.el9_3); before 4:4.9.4-3.el9_4 (fixed in 4:4.9.4-3.el9_4)
  • Red Hat Red Hat Enterprise Linux 9.0 Extended Update Support: before 1:1.26.7-1.el9_0 (fixed in 1:1.26.7-1.el9_0); before 2:4.2.0-3.el9_0 (fixed in 2:4.2.0-3.el9_0)
  • Red Hat Red Hat Enterprise Linux 9.2 Extended Update Support: before 1:1.29.3-1.el9_2 (fixed in 1:1.29.3-1.el9_2); before 2:4.4.1-16.el9_2 (fixed in 2:4.4.1-16.el9_2)
  • Red Hat Red Hat Openshift Container Platform 3.11
  • Red Hat Red Hat Openshift Container Platform 4.12: before 3:4.4.1-3.2.rhaos4.12.el8 (fixed in 3:4.4.1-3.2.rhaos4.12.el8)
  • Red Hat Red Hat Openshift Container Platform 4.13: before 3:4.4.1-5.3.rhaos4.13.el8 (fixed in 3:4.4.1-5.3.rhaos4.13.el8); before 3:4.4.1-7.3.rhaos4.13.el8 (fixed in 3:4.4.1-7.3.rhaos4.13.el8)
  • Red Hat Red Hat Openshift Container Platform 4.14: before 3:4.4.1-13.4.rhaos4.14.el8 (fixed in 3:4.4.1-13.4.rhaos4.14.el8)
  • Red Hat Red Hat Openshift Container Platform 4.15: before 3:4.4.1-23.2.rhaos4.15.el8 (fixed in 3:4.4.1-23.2.rhaos4.15.el8)

Published 2024-03-18. Last modified 2026-09-25.