CVE-2024-9676: Red Hat Enterprise Linux
Medium severity, CVSS 6.5. EPSS: 1.3% chance of exploitation in the next 30 days.
A vulnerability was found in Podman, Buildah, and CRI-O. A symlink traversal vulnerability in the containers/storage library can cause Podman, Buildah, and CRI-O to hang and result in a denial of service via OOM kill when running a malicious image using an automatically assigned user namespace (`--userns=auto` in Podman and Buildah). The containers/storage library will read /etc/passwd inside the container, but does not properly validate if that file is a symlink, which can be used to cause the library to read an arbitrary file on the host.
Affected products
- Red Hat Enterprise Linux: version 9.0 only
- Red Hat Enterprise Linux Eus: version 9.4 only
- Red Hat Enterprise Linux For Arm 64: version 9.0_aarch64 only
- Red Hat Enterprise Linux For Arm 64 Eus: version 9.4_aarch64 only
- Red Hat Enterprise Linux For IBM Z Systems: version 9.0_s390x only
- Red Hat Enterprise Linux For IBM Z Systems Eus: version 9.4_s390x only
- Red Hat Enterprise Linux For Power Little Endian: version 9.0_ppc64le only
- Red Hat Enterprise Linux For Power Little Endian Eus: version 9.4_ppc64le only
- Red Hat Enterprise Linux Server Aus: version 9.4 only
- Red Hat Enterprise Linux Server For Power Little Endian Update Services For SAP Solutions: version 9.4_ppc64le only
- Red Hat Openshift Container Platform: version 4.12 only; version 4.13 only; version 4.14 only; version 4.15 only; version 4.16 only; version 4.17 only
- Red Hat Openshift Container Platform For ARM64: version 4.12 only; version 4.13 only; version 4.14 only; version 4.15 only; version 4.16 only
- Red Hat Openshift Container Platform For IBM Z: version 4.12 only; version 4.13 only; version 4.14 only; version 4.15 only; version 4.16 only
- Red Hat Openshift Container Platform For Linuxone: version 4.12 only; version 4.13 only; version 4.14 only; version 4.15 only; version 4.16 only
- Red Hat Openshift Container Platform For Power: version 4.12 only; version 4.13 only; version 4.14 only; version 4.15 only; version 4.16 only
Published 2024-10-15. Last modified 2026-06-17.