MEDIUM4.4
GHSA-586p-749j-fhwp
Buildah allows arbitrary directory mount
Quick fix
GHSA-586p-749j-fhwp — github.com/containers/buildah: upgrade to the fixed version with the command below.
go get github.com/containers/buildah@v1.38.0Details
A vulnerability was found in Buildah. Cache mounts do not properly validate that user-specified paths for the cache are within our cache directory, allowing a `RUN` instruction in a Container file to mount an arbitrary directory from the host (read/write) into the container as long as those files can be accessed by the user running Buildah.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/containers/buildah
Introduced in:
0Fixed in: 1.38.0Fix
go get github.com/containers/buildah@v1.38.0References
- https://nvd.nist.gov/vuln/detail/CVE-2024-9675[ADVISORY]
- https://github.com/containers/buildah/commit/aa67e5d71ee7ec07122a210baa3b13966a9e086c[WEB]
- https://pkg.go.dev/vuln/GO-2024-3186[WEB]
- https://github.com/containers/buildah[PACKAGE]
- https://bugzilla.redhat.com/show_bug.cgi?id=2317458[WEB]
- https://access.redhat.com/security/cve/CVE-2024-9675[WEB]
- https://access.redhat.com/errata/RHSA-2025:3573[WEB]
- https://access.redhat.com/errata/RHSA-2025:3301[WEB]
- https://access.redhat.com/errata/RHSA-2025:2710[WEB]
- https://access.redhat.com/errata/RHSA-2025:2701[WEB]
- https://access.redhat.com/errata/RHSA-2025:2454[WEB]
- https://access.redhat.com/errata/RHSA-2025:2449[WEB]
- https://access.redhat.com/errata/RHSA-2025:2445[WEB]
- https://access.redhat.com/errata/RHSA-2024:9459[WEB]
- https://access.redhat.com/errata/RHSA-2024:9454[WEB]
- https://access.redhat.com/errata/RHSA-2024:9051[WEB]
- https://access.redhat.com/errata/RHSA-2024:8994[WEB]
- https://access.redhat.com/errata/RHSA-2024:8984[WEB]
- https://access.redhat.com/errata/RHSA-2024:8846[WEB]
- https://access.redhat.com/errata/RHSA-2024:8709[WEB]
- https://access.redhat.com/errata/RHSA-2024:8708[WEB]
- https://access.redhat.com/errata/RHSA-2024:8707[WEB]
- https://access.redhat.com/errata/RHSA-2024:8703[WEB]
- https://access.redhat.com/errata/RHSA-2024:8700[WEB]
- https://access.redhat.com/errata/RHSA-2024:8690[WEB]
- https://access.redhat.com/errata/RHSA-2024:8686[WEB]
- https://access.redhat.com/errata/RHSA-2024:8679[WEB]
- https://access.redhat.com/errata/RHSA-2024:8675[WEB]
- https://access.redhat.com/errata/RHSA-2024:8563[WEB]
- https://access.redhat.com/errata/RHBA-2024:10967[WEB]