INFSA-2025:1372: container-tools:rhel8 security update

Information about definition

Identificator: INFSA-2025:1372

Type: security

Release date: 2025-03-17 13:07:50 UTC

Information about package

The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.

Vulnerabilities description

  • CVE-2024-11218

    A vulnerability was found in `podman build` and `buildah.` This issue occurs in a container breakout by using --jobs=2 and a race condition when building a malicious Containerfile. SELinux might mitigate it, but even with SELinux on, it still allows the enumeration of files and directories on the host.

Severity level

CVE Score CVSS 2.0 Score CVSS 3.x Score CVSS 4.0
no information 8.6 no information
Critical, important, moderate, low

Updated packages