{"id":"RLSA-2024:8846","summary":"Important: container-tools:rhel8 security update","details":"The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.\n\nSecurity Fix(es):\n\n* Podman: Buildah: cri-o: FIPS Crypto-Policy Directory Mounting Issue in containers/common Go Library (CVE-2024-9341)\n\n* Buildah: Podman: Improper Input Validation in bind-propagation Option of Dockerfile RUN --mount Instruction (CVE-2024-9407)\n\n* buildah: Buildah allows arbitrary directory mount (CVE-2024-9675)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.","modified":"2026-03-11T06:30:10.012558Z","published":"2024-11-08T15:56:47.559546Z","related":["CVE-2024-9341","CVE-2024-9407","CVE-2024-9675"],"references":[{"type":"ADVISORY","url":"https://errata.rockylinux.org/RLSA-2024:8846"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2315691"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2315887"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2317458"}],"affected":[{"package":{"name":"aardvark-dns","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/aardvark-dns?distro=rocky-linux-8&epoch=2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:1.10.1-2.module+el8.10.0+1874+ce489889"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2024:8846.json"}},{"package":{"name":"buildah","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/buildah?distro=rocky-linux-8&epoch=2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:1.33.10-1.module+el8.10.0+1880+8e896d1b"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2024:8846.json"}},{"package":{"name":"cockpit-podman","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/cockpit-podman?distro=rocky-linux-8&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:84.1-1.module+el8.10.0+1815+5fe7415e"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2024:8846.json"}},{"package":{"name":"conmon","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/conmon?distro=rocky-linux-8&epoch=3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3:2.1.10-1.module+el8.10.0+1815+5fe7415e"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2024:8846.json"}},{"package":{"name":"containernetworking-plugins","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/containernetworking-plugins?distro=rocky-linux-8&epoch=1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:1.4.0-5.module+el8.10.0+1843+6892ab28"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2024:8846.json"}},{"package":{"name":"containers-common","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/containers-common?distro=rocky-linux-8&epoch=2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:1-82.module+el8.10.0+1843+6892ab28"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2024:8846.json"}},{"package":{"name":"container-selinux","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/container-selinux?distro=rocky-linux-8&epoch=2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:2.229.0-2.module+el8.10.0+1815+5fe7415e"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2024:8846.json"}},{"package":{"name":"criu","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/criu?distro=rocky-linux-8&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:3.18-5.module+el8.10.0+1815+5fe7415e"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2024:8846.json"}},{"package":{"name":"crun","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/crun?distro=rocky-linux-8&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.14.3-2.module+el8.10.0+1815+5fe7415e"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2024:8846.json"}},{"package":{"name":"fuse-overlayfs","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/fuse-overlayfs?distro=rocky-linux-8&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.13-1.module+el8.10.0+1815+5fe7415e"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2024:8846.json"}},{"package":{"name":"libslirp","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/libslirp?distro=rocky-linux-8&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:4.4.0-2.module+el8.10.0+1815+5fe7415e"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2024:8846.json"}},{"package":{"name":"netavark","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/netavark?distro=rocky-linux-8&epoch=2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:1.10.3-1.module+el8.10.0+1815+5fe7415e"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2024:8846.json"}},{"package":{"name":"oci-seccomp-bpf-hook","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/oci-seccomp-bpf-hook?distro=rocky-linux-8&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.2.10-1.module+el8.10.0+1815+5fe7415e"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2024:8846.json"}},{"package":{"name":"podman","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/podman?distro=rocky-linux-8&epoch=4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4:4.9.4-15.module+el8.10.0+1880+8e896d1b"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2024:8846.json"}},{"package":{"name":"python-podman","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/python-podman?distro=rocky-linux-8&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:4.9.0-2.module+el8.10.0+1843+6892ab28"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2024:8846.json"}},{"package":{"name":"runc","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/runc?distro=rocky-linux-8&epoch=1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:1.1.12-5.module+el8.10.0+1874+ce489889"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2024:8846.json"}},{"package":{"name":"skopeo","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/skopeo?distro=rocky-linux-8&epoch=2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:1.14.5-3.module+el8.10.0+1843+6892ab28"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2024:8846.json"}},{"package":{"name":"slirp4netns","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/slirp4netns?distro=rocky-linux-8&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.2.3-1.module+el8.10.0+1815+5fe7415e"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2024:8846.json"}},{"package":{"name":"toolbox","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/toolbox?distro=rocky-linux-8&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:0.0.99.5-2.module+el8.10.0+1815+5fe7415e.rocky.0.2.rocky.0.2"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2024:8846.json"}},{"package":{"name":"udica","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/udica?distro=rocky-linux-8&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:0.2.6-21.module+el8.10.0+1815+5fe7415e"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2024:8846.json"}}],"schema_version":"1.7.5","credits":[{"name":"Rocky Enterprise Software Foundation"},{"name":"Red Hat"}]}