ALSA-2024%3A9459
The buildah package provides a tool for facilitating building OCI container images. Among other things, buildah enables you to: Create a working container, either from scratch or using an image as a starting point; Create an image, either from a working container or using the instructions in a Dockerfile; Build both Docker and OCI images. Security Fix(es): * go/parser: golang: Calling any of the Parse functions containing deeply nested literals can cause a panic/stack exhaustion (CVE-2024-34155) * encoding/gob: golang: Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion (CVE-2024-34156) * go/build/constraint: golang: Calling Parse on a "// +build" build tag line with deeply nested expressions can cause a panic due to stack exhaustion (CVE-2024-34158) * Podman: Buildah: cri-o: FIPS Crypto-Policy Directory Mounting Issue in containers/common Go Library (CVE-2024-9341) * Buildah: Podman: Improper Input Validation in bind-propagation Option of Dockerfile RUN --mount Instruction (CVE-2024-9407) * buildah: Buildah allows arbitrary directory mount (CVE-2024-9675) * Podman: Buildah: CRI-O: symlink traversal vulnerability in the containers/storage library can cause Denial of Service (DoS) (CVE-2024-9676) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| AlmaLinux:9 | buildah-tests | 0, 0 |
| AlmaLinux:9 | buildah | 0, 0 |
Timeline
- Nov 12, 2024 CVE Published
- Nov 18, 2024 CVE Updated
- Mar 6, 2026 Distribution Patch
- Mar 6, 2026 Distribution Patch
- Mar 6, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2024:9459 vendor-advisory
- https://access.redhat.com/security/cve/CVE-2024-34155 third-party-advisory
- https://access.redhat.com/security/cve/CVE-2024-34156 third-party-advisory
- https://access.redhat.com/security/cve/CVE-2024-34158 third-party-advisory
- https://access.redhat.com/security/cve/CVE-2024-9341 third-party-advisory
- https://access.redhat.com/security/cve/CVE-2024-9407 third-party-advisory
- https://access.redhat.com/security/cve/CVE-2024-9675 third-party-advisory
- https://access.redhat.com/security/cve/CVE-2024-9676 third-party-advisory
- https://bugzilla.redhat.com/2310527 third-party-advisory
- https://bugzilla.redhat.com/2310528 third-party-advisory
- https://bugzilla.redhat.com/2310529 third-party-advisory
- https://bugzilla.redhat.com/2315691 third-party-advisory
- https://bugzilla.redhat.com/2315887 third-party-advisory
- https://bugzilla.redhat.com/2317458 third-party-advisory
- https://bugzilla.redhat.com/2317467 third-party-advisory
- https://errata.almalinux.org/9/ALSA-2024-9459.html vendor-advisory