CVE-2024-9341

Source
https://cve.org/CVERecord?id=CVE-2024-9341
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-9341.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-9341
Aliases
Downstream
AZL (5)
BELL (1)
CGA (12)
CLEANSTART (1)
CLSA (3)
DEBIAN (1)
MGASA (1)
OESA (6)
openSUSE (4)
RHSA (11)
RLSA (1)
SUSE (8)
UBUNTU (1)
Related
Published
2024-10-01T18:52:00Z
Modified
2026-08-13T03:52:06Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:N CVSS Calculator
Summary
Podman: buildah: cri-o: fips crypto-policy directory mounting issue in containers/common go library
Details

A flaw was found in Go. When FIPS mode is enabled on a system, container runtimes may incorrectly handle certain file paths due to improper validation in the containers/common Go library. This flaw allows an attacker to exploit symbolic links and trick the system into mounting sensitive host directories inside a container. This issue also allows attackers to access critical host files, bypassing the intended isolation between containers and the host system.

Database specific
{
    "cna_assigner":  "redhat",
    "cwe_ids":  [
        "CWE-59"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/9xxx/CVE-2024-9341.json"
}
References

Affected packages

Git / github.com/containers/common

Affected ranges

Type
GIT
Repo
https://github.com/containers/common
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "fixed":  "0.60.4"
        }
    ],
    "source":  "AFFECTED_FIELD"
}

Affected versions

Other
list
v0.*
v0.0.2
v0.31.1
v0.60.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-9341.json"