Intel

AIKIDO-2024-10108

github.com/containers/buildah is vulnerable to Improper Privilege Management

Improper Privilege ManagementCVE-2024-1753 Published May 27, 2024

86

High Risk

This Affects:

Gogithub.com/containers/buildah
1.24.0 - 1.24.6
Fixed in 1.24.7
1.26.0 - 1.26.6
Fixed in 1.26.7
1.27.0 - 1.27.3
Fixed in 1.27.4
1.29.0 - 1.29.2
Fixed in 1.29.3
1.31.0 - 1.31.4
Fixed in 1.31.5
1.32.0 - 1.32.2
Fixed in 1.32.3
1.33.0 - 1.33.6
Fixed in 1.33.7
1.34.0 - 1.34.2
Fixed in 1.34.3
1.35.0 - 1.35.0
Fixed in 1.35.1
Are you affected? Scan for Free

TL;DR

Affected versions of the package are vulnerable to improper privilege management. Users running containers with root privileges allow a container to run with read/write access to the host system files when SELinux is not enabled. With SELinux enabled, some read access is allowed.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

github.com/containers/buildah is vulnerable to Improper Privilege Management in versions 1.35.0 - 1.35.0, 1.34.0 - 1.34.2, 1.33.0 - 1.33.6, 1.32.0 - 1.32.2, 1.31.0 - 1.31.4, 1.29.0 - 1.29.2, 1.27.0 - 1.27.3, 1.26.0 - 1.26.6 and 1.24.0 - 1.24.6.

How to fix this

Upgrade the github.com/containers/buildah library to the patch version.

Links

Other

access.redhat.com/errata/RHSA-2024:2049
https://access.redhat.com/errata/RHSA-2024:2049
access.redhat.com/errata/RHSA-2024:2055
https://access.redhat.com/errata/RHSA-2024:2055
access.redhat.com/errata/RHSA-2024:2064
https://access.redhat.com/errata/RHSA-2024:2064
access.redhat.com/errata/RHSA-2024:2066
https://access.redhat.com/errata/RHSA-2024:2066
access.redhat.com/errata/RHSA-2024:2077
https://access.redhat.com/errata/RHSA-2024:2077
access.redhat.com/errata/RHSA-2024:2084
https://access.redhat.com/errata/RHSA-2024:2084
access.redhat.com/errata/RHSA-2024:2089
https://access.redhat.com/errata/RHSA-2024:2089
access.redhat.com/errata/RHSA-2024:2090
https://access.redhat.com/errata/RHSA-2024:2090
access.redhat.com/errata/RHSA-2024:2097
https://access.redhat.com/errata/RHSA-2024:2097
access.redhat.com/errata/RHSA-2024:2098
https://access.redhat.com/errata/RHSA-2024:2098
access.redhat.com/errata/RHSA-2024:2548
https://access.redhat.com/errata/RHSA-2024:2548
access.redhat.com/errata/RHSA-2024:2645
https://access.redhat.com/errata/RHSA-2024:2645
access.redhat.com/errata/RHSA-2024:2669
https://access.redhat.com/errata/RHSA-2024:2669
access.redhat.com/errata/RHSA-2024:2672
https://access.redhat.com/errata/RHSA-2024:2672
access.redhat.com/errata/RHSA-2024:2784
https://access.redhat.com/errata/RHSA-2024:2784
access.redhat.com/errata/RHSA-2024:2877
https://access.redhat.com/errata/RHSA-2024:2877
access.redhat.com/errata/RHSA-2024:3254
https://access.redhat.com/errata/RHSA-2024:3254
access.redhat.com/security/cve/CVE-2024-1753
https://access.redhat.com/security/cve/CVE-2024-1753
bugzilla.redhat.com/show_bug.cgi?id=2265513
https://bugzilla.redhat.com/show_bug.cgi?id=2265513
pkg.go.dev/vuln/GO-2024-2658
https://pkg.go.dev/vuln/GO-2024-2658
lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FCRZVUDOFM5CPREQKBEU2VK2QK62PSBP/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FCRZVUDOFM5CPREQKBEU2VK2QK62PSBP/
lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KOYMVMQ7RWMDTSKQTBO734BE3WQPI2AJ/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KOYMVMQ7RWMDTSKQTBO734BE3WQPI2AJ/
lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZVBSVZGVABPYIHK5HZM472NPGWMI7WXH/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZVBSVZGVABPYIHK5HZM472NPGWMI7WXH/