Medium severity6.5OSV Advisory· Published Oct 15, 2024· Updated Jun 17, 2026
CVE-2024-9676
CVE-2024-9676
Description
A vulnerability was found in Podman, Buildah, and CRI-O. A symlink traversal vulnerability in the containers/storage library can cause Podman, Buildah, and CRI-O to hang and result in a denial of service via OOM kill when running a malicious image using an automatically assigned user namespace (--userns=auto in Podman and Buildah). The containers/storage library will read /etc/passwd inside the container, but does not properly validate if that file is a symlink, which can be used to cause the library to read an arbitrary file on the host.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
109- Range: V1.2, v1, v1.1, …
- osv-coords69 versionspkg:rpm/suse/buildah&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOSpkg:rpm/suse/buildah&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP4pkg:rpm/suse/buildah&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-LTSSpkg:rpm/suse/buildah&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP4-LTSSpkg:rpm/suse/buildah&distro=SUSE%20Enterprise%20Storage%207.1pkg:rpm/suse/podman&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP3-LTSSpkg:rpm/suse/buildah&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP3-LTSSpkg:rpm/suse/buildah&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP3-LTSSpkg:rpm/suse/buildah&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP3pkg:rpm/suse/podman&distro=SUSE%20Linux%20Enterprise%20Micro%205.5pkg:rpm/suse/podman&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Containers%2015%20SP5pkg:rpm/suse/podman&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Containers%2015%20SP6pkg:rpm/opensuse/podman&distro=openSUSE%20Leap%20Micro%205.5pkg:rpm/opensuse/podman&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/podman&distro=openSUSE%20Leap%2015.6pkg:rpm/suse/buildah&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Containers%2015%20SP5pkg:rpm/suse/buildah&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Containers%2015%20SP6pkg:rpm/opensuse/buildah&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/buildah&distro=openSUSE%20Leap%2015.6pkg:rpm/suse/podman&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP3pkg:rpm/suse/podman&distro=SUSE%20Linux%20Enterprise%20Micro%205.1pkg:rpm/suse/podman&distro=SUSE%20Linux%20Enterprise%20Micro%205.2pkg:rpm/suse/podman&distro=SUSE%20Enterprise%20Storage%207.1pkg:rpm/suse/podman&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP4pkg:rpm/suse/podman&distro=SUSE%20Linux%20Micro%206.0pkg:rpm/suse/skopeo&distro=SUSE%20Linux%20Micro%206.0pkg:rpm/suse/podman&distro=SUSE%20Linux%20Enterprise%20Micro%205.3pkg:rpm/suse/podman&distro=SUSE%20Linux%20Enterprise%20Micro%205.4pkg:rpm/suse/podman&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOSpkg:rpm/suse/podman&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-LTSSpkg:rpm/suse/podman&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP4-LTSSpkg:rpm/opensuse/buildah&distro=openSUSE%20Tumbleweedpkg:rpm/almalinux/aardvark-dnspkg:rpm/almalinux/buildahpkg:rpm/almalinux/buildah-testspkg:rpm/almalinux/cockpit-podmanpkg:rpm/almalinux/conmonpkg:rpm/almalinux/container-selinuxpkg:rpm/almalinux/containernetworking-pluginspkg:rpm/almalinux/containers-commonpkg:rpm/almalinux/critpkg:rpm/almalinux/criupkg:rpm/almalinux/criu-develpkg:rpm/almalinux/criu-libspkg:rpm/almalinux/crunpkg:rpm/almalinux/fuse-overlayfspkg:rpm/almalinux/libslirppkg:rpm/almalinux/libslirp-develpkg:rpm/almalinux/netavarkpkg:rpm/almalinux/oci-seccomp-bpf-hookpkg:rpm/almalinux/podmanpkg:rpm/almalinux/podman-catatonitpkg:rpm/almalinux/podman-dockerpkg:rpm/almalinux/podman-gvproxypkg:rpm/almalinux/podman-pluginspkg:rpm/almalinux/podman-remotepkg:rpm/almalinux/podman-testspkg:rpm/almalinux/python3-criupkg:rpm/almalinux/python3-podmanpkg:rpm/almalinux/runcpkg:rpm/almalinux/skopeopkg:rpm/almalinux/skopeo-testspkg:rpm/almalinux/slirp4netnspkg:rpm/almalinux/toolboxpkg:rpm/almalinux/toolbox-testspkg:rpm/almalinux/udicapkg:rpm/suse/podman&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP3-LTSSpkg:rpm/opensuse/podman&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/skopeo&distro=openSUSE%20Tumbleweed
< 1.35.4-150400.3.33.1+ 68 more
- (no CPE)range: < 1.35.4-150400.3.33.1
- (no CPE)range: < 1.35.4-150400.3.33.1
- (no CPE)range: < 1.35.4-150400.3.33.1
- (no CPE)range: < 1.35.4-150400.3.33.1
- (no CPE)range: < 1.35.4-150300.8.28.3
- (no CPE)range: < 4.9.5-150300.9.43.1
- (no CPE)range: < 1.35.4-150300.8.28.3
- (no CPE)range: < 1.35.4-150300.8.28.3
- (no CPE)range: < 1.35.4-150300.8.28.3
- (no CPE)range: < 4.9.5-150500.3.28.1
- (no CPE)range: < 4.9.5-150500.3.28.1
- (no CPE)range: < 4.9.5-150500.3.28.1
- (no CPE)range: < 4.9.5-150500.3.28.1
- (no CPE)range: < 4.9.5-150500.3.28.1
- (no CPE)range: < 4.9.5-150500.3.28.1
- (no CPE)range: < 1.35.4-150500.3.19.1
- (no CPE)range: < 1.35.4-150500.3.19.1
- (no CPE)range: < 1.35.4-150500.3.19.1
- (no CPE)range: < 1.35.4-150500.3.19.1
- (no CPE)range: < 4.9.5-150300.9.43.1
- (no CPE)range: < 4.9.5-150300.9.43.1
- (no CPE)range: < 4.9.5-150300.9.43.1
- (no CPE)range: < 4.9.5-150300.9.43.1
- (no CPE)range: < 4.9.5-150400.4.35.1
- (no CPE)range: < 4.9.5-2.1
- (no CPE)range: < 1.14.4-2.1
- (no CPE)range: < 4.9.5-150400.4.35.1
- (no CPE)range: < 4.9.5-150400.4.35.1
- (no CPE)range: < 4.9.5-150400.4.35.1
- (no CPE)range: < 4.9.5-150400.4.35.1
- (no CPE)range: < 4.9.5-150400.4.35.1
- (no CPE)range: < 1.37.5-1.1
- (no CPE)range: < 2:1.10.1-2.module_el8.10.0+3909+6e1c1eb7
- (no CPE)range: < 2:1.33.11-1.module_el8.10.0+3926+f12484f5
- (no CPE)range: < 2:1.33.11-1.module_el8.10.0+3926+f12484f5
- (no CPE)range: < 84.1-1.module_el8.10.0+3876+e55593a8
- (no CPE)range: < 3:2.1.10-1.module_el8.10.0+3876+e55593a8
- (no CPE)range: < 2:2.229.0-2.module_el8.10.0+3909+6e1c1eb7
- (no CPE)range: < 1:1.4.0-5.module_el8.10.0+3876+e55593a8
- (no CPE)range: < 2:1-82.module_el8.10.0+3876+e55593a8
- (no CPE)range: < 3.18-5.module_el8.10.0+3901+4b80ecd7
- (no CPE)range: < 3.18-5.module_el8.10.0+3926+f12484f5
- (no CPE)range: < 3.18-5.module_el8.10.0+3876+e55593a8
- (no CPE)range: < 3.18-5.module_el8.10.0+3845+87b84552
- (no CPE)range: < 1.14.3-2.module_el8.10.0+3845+87b84552
- (no CPE)range: < 1.13-1.module_el8.10.0+3909+6e1c1eb7
- (no CPE)range: < 4.4.0-2.module_el8.10.0+3876+e55593a8
- (no CPE)range: < 4.4.0-2.module_el8.10.0+3909+6e1c1eb7
- (no CPE)range: < 2:1.10.3-1.module_el8.10.0+3926+f12484f5
- (no CPE)range: < 1.2.10-1.module_el8.10.0+3909+6e1c1eb7
- (no CPE)range: < 4:4.9.4-18.module_el8.10.0+3926+f12484f5
- (no CPE)range: < 4:4.9.4-18.module_el8.10.0+3926+f12484f5
- (no CPE)range: < 4:4.9.4-18.module_el8.10.0+3926+f12484f5
- (no CPE)range: < 4:4.9.4-18.module_el8.10.0+3926+f12484f5
- (no CPE)range: < 4:4.9.4-18.module_el8.10.0+3926+f12484f5
- (no CPE)range: < 4:4.9.4-18.module_el8.10.0+3926+f12484f5
- (no CPE)range: < 4:4.9.4-18.module_el8.10.0+3926+f12484f5
- (no CPE)range: < 3.18-5.module_el8.10.0+3858+6ad51f9f
- (no CPE)range: < 4.9.0-3.module_el8.10.0+3926+f12484f5
- (no CPE)range: < 1:1.1.12-5.module_el8.10.0+3909+6e1c1eb7
- (no CPE)range: < 2:1.14.5-3.module_el8.10.0+3926+f12484f5
- (no CPE)range: < 2:1.14.5-3.module_el8.10.0+3876+e55593a8
- (no CPE)range: < 1.2.3-1.module_el8.10.0+3845+87b84552
- (no CPE)range: < 0.0.99.5-2.module_el8.10.0+3901+4b80ecd7
- (no CPE)range: < 0.0.99.5-2.module_el8.10.0+3858+6ad51f9f
- (no CPE)range: < 0.2.6-21.module_el8.10.0+3926+f12484f5
- (no CPE)range: < 4.9.5-150300.9.43.1
- (no CPE)range: < 5.2.4-3.1
- (no CPE)range: < 1.16.1-2.1
cpe:2.3:a:redhat:openshift_container_platform:4.12:*:*:*:*:*:*:*+ 15 more
- cpe:2.3:a:redhat:openshift_container_platform:4.12:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_container_platform:4.13:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_container_platform:4.14:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_container_platform:4.15:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_container_platform:4.16:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_container_platform:4.17:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_container_platform_for_arm64:4.12:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_container_platform_for_arm64:4.13:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_container_platform_for_arm64:4.14:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_container_platform_for_arm64:4.15:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_container_platform_for_arm64:4.16:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_container_platform_for_power:4.12:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_container_platform_for_power:4.13:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_container_platform_for_power:4.14:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_container_platform_for_power:4.15:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_container_platform_for_power:4.16:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_container_platform_for_ibm_z:4.12:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:redhat:openshift_container_platform_for_ibm_z:4.12:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_container_platform_for_ibm_z:4.13:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_container_platform_for_ibm_z:4.14:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_container_platform_for_ibm_z:4.15:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_container_platform_for_ibm_z:4.16:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_container_platform_for_linuxone:4.12:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:redhat:openshift_container_platform_for_linuxone:4.12:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_container_platform_for_linuxone:4.13:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_container_platform_for_linuxone:4.14:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_container_platform_for_linuxone:4.15:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_container_platform_for_linuxone:4.16:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_eus:9.4:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_for_arm_64:9.0_aarch64:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_for_arm_64_eus:9.4_aarch64:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:redhat:enterprise_linux_for_arm_64_eus:9.4_aarch64:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:9.4_s390x:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:9.0_s390x:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian:9.0_ppc64le:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:9.4_ppc64le:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_server_aus:9.4:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions:9.4_ppc64le:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
21- access.redhat.com/errata/RHSA-2024:8418nvdVendor Advisory
- access.redhat.com/errata/RHSA-2024:8428nvdVendor Advisory
- access.redhat.com/errata/RHSA-2024:8437nvdVendor Advisory
- access.redhat.com/errata/RHSA-2024:8686nvdVendor Advisory
- access.redhat.com/errata/RHSA-2024:8690nvdVendor Advisory
- access.redhat.com/errata/RHSA-2024:8694nvdVendor Advisory
- access.redhat.com/errata/RHSA-2024:8700nvdVendor Advisory
- access.redhat.com/errata/RHSA-2024:8984nvdVendor Advisory
- access.redhat.com/errata/RHSA-2024:9051nvdVendor Advisory
- access.redhat.com/errata/RHSA-2024:9454nvdVendor Advisory
- access.redhat.com/errata/RHSA-2024:9459nvdVendor Advisory
- access.redhat.com/errata/RHSA-2024:9926nvdVendor Advisory
- access.redhat.com/security/cve/CVE-2024-9676nvdVendor Advisory
- github.com/advisories/GHSA-wq2p-5pc6-wpgfnvdThird Party Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue Tracking
- access.redhat.com/errata/RHSA-2024:10289nvd
- access.redhat.com/errata/RHSA-2025:0876nvd
- access.redhat.com/errata/RHSA-2025:2454nvd
- access.redhat.com/errata/RHSA-2025:2710nvd
- access.redhat.com/errata/RHSA-2025:3301nvd
- github.com/containers/storage/commit/935c58f4b3e364a9c9d33ed06476a831e6ad5679nvd
News mentions
0No linked articles in our index yet.