LiveActive security incident?Get immediate response
CVE Record

CVE-2024-11218: Podman: buildah: container breakout by using --jobs=2 and a race condition when building a malicious containerfile

A vulnerability was found in `podman build` and `buildah.` This issue occurs in a container breakout by using --jobs=2 and a race condition when building a malicious Containerfile. SELinux might mitigate it, but even with SELinux on, it still allows the enumeration of files and directories on the host.

HighCVSS 8.6Not KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

CVE-2024-11218 is a high-severity Podman/Buildah build flaw. If a system builds a malicious Containerfile with affected tooling, a race condition can allow escape from the build container to the host. SELinux may reduce impact, but the source says host file and directory enumeration can still occur.

Executive priority

Treat this as a priority patching and build-pipeline control issue, especially for CI or shared build infrastructure. The business risk is host compromise from malicious container build input, not broad unauthenticated remote exploitation based on the provided evidence.

Technical view

The issue affects podman build and buildah when building a malicious Containerfile using parallel build jobs. The CVSS 3.1 score is 8.6, with local attack vector, required user interaction, changed scope, and high confidentiality, integrity, and availability impact. Affected Red Hat packages include podman, buildah, container-tools:rhel8, and rhcos across listed RHEL and OpenShift streams.

Likely exposure

Highest exposure is on RHEL or OpenShift build hosts, CI runners, developer workstations, or automation that builds Containerfiles from untrusted users, repositories, pull requests, or third parties using affected Podman or Buildah packages.

Exploitation context

The bundle does not show CISA KEV listing or active exploitation. Exploitation requires a malicious Containerfile to be built with vulnerable tooling and user interaction. This is most relevant where untrusted build definitions can reach privileged or sensitive host build environments.

Researcher notes

Evidence supports a race condition tied to Podman/Buildah parallel builds and malicious Containerfiles. SELinux may mitigate breakout impact but still permits host enumeration. The bundle lists affected Red Hat products and advisories, but does not provide exploit telemetry or full fixed-version details.

Mitigation direction

  • Apply the relevant Red Hat security advisories for affected RHEL and OpenShift packages.
  • Check vendor guidance for fixed package versions before relying on local assumptions.
  • Avoid building untrusted Containerfiles on affected Podman or Buildah versions.
  • Restrict who can submit or trigger container builds in CI and shared environments.
  • Keep SELinux enforcing, but do not treat it as a complete mitigation.

Validation and detection

  • Inventory Podman, Buildah, container-tools, and RHCOS versions against listed affected packages.
  • Identify CI runners and developer systems that build external or user-submitted Containerfiles.
  • Confirm relevant Red Hat advisories have been applied to affected platforms.
  • Review build pipelines for parallel build usage and untrusted Containerfile inputs.
  • Verify SELinux enforcement and least-privilege controls on build hosts.
Prepared
Confidence
medium
Sources
12

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · medium confidence lookup

CWE-269: Authorization and privilege behavior lookup

Authorization weaknesses can support privilege escalation and valid-account review, depending on exploit path. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
description · low confidence lookup

Container behavior lookup

The affected technology mentions containers, so container-specific ATT&CK technique review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2024-11218 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
High
CVSS
8.6 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
5Timeline events
1ADP providers
33Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: noTechnical Impact: total

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
8.6CVSS 3.1HighCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H1.86redhat

Vulnerability scoring details

Base CVSS 3.1 score

8.6High
CVSS 3.1 vector shape for CVE-2024-11218Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. Source timelineredhat

    Reported to Red Hat.

  2. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  3. Source timelineredhat

    Made public.

  4. CVE publishedCVE Program

    The CVE record was published.

  5. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CISA-ADPCISA ADP Vulnrichment
other:ssvc

Source materials

  • CVE List V5 sourceCVE List V5
  • RHSA-2025:0830CVE reference, redhat · vendor-advisory, x_refsource_REDHAT
  • RHSA-2025:0878CVE reference, redhat · vendor-advisory, x_refsource_REDHAT
  • RHSA-2025:0922CVE reference, redhat · vendor-advisory, x_refsource_REDHAT
  • RHSA-2025:0923CVE reference, redhat · vendor-advisory, x_refsource_REDHAT
  • RHSA-2025:1186CVE reference, redhat · vendor-advisory, x_refsource_REDHAT
  • RHSA-2025:1187CVE reference, redhat · vendor-advisory, x_refsource_REDHAT
  • RHSA-2025:1188CVE reference, redhat · vendor-advisory, x_refsource_REDHAT
  • RHSA-2025:1189CVE reference, redhat · vendor-advisory, x_refsource_REDHAT
  • RHSA-2025:1207CVE reference, redhat · vendor-advisory, x_refsource_REDHAT
  • RHSA-2025:1275CVE reference, redhat · vendor-advisory, x_refsource_REDHAT
  • RHSA-2025:1295CVE reference, redhat · vendor-advisory, x_refsource_REDHAT
  • RHSA-2025:1296CVE reference, redhat · vendor-advisory, x_refsource_REDHAT
  • RHSA-2025:1372CVE reference, redhat · vendor-advisory, x_refsource_REDHAT
  • RHSA-2025:1453CVE reference, redhat · vendor-advisory, x_refsource_REDHAT
  • RHSA-2025:1707CVE reference, redhat · vendor-advisory, x_refsource_REDHAT
  • RHSA-2025:1713CVE reference, redhat · vendor-advisory, x_refsource_REDHAT
  • RHSA-2025:1908CVE reference, redhat · vendor-advisory, x_refsource_REDHAT
  • RHSA-2025:1910CVE reference, redhat · vendor-advisory, x_refsource_REDHAT
  • RHSA-2025:1914CVE reference, redhat · vendor-advisory, x_refsource_REDHAT
  • RHSA-2025:2441CVE reference, redhat · vendor-advisory, x_refsource_REDHAT
  • RHSA-2025:2443CVE reference, redhat · vendor-advisory, x_refsource_REDHAT
  • RHSA-2025:2454CVE reference, redhat · vendor-advisory, x_refsource_REDHAT
  • RHSA-2025:2456CVE reference, redhat · vendor-advisory, x_refsource_REDHAT
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
Unknown vendorbuildahbuildah, 0, 1.35.0, 1.37.0, 1.38.0unaffected
Red HatRed Hat Enterprise Linux 8container-tools:rhel8, 8100020250124120243.afee755daffected
Red HatRed Hat Enterprise Linux 8.6 Advanced Mission Critical Update Supportcontainer-tools:rhel8, 8060020250203202123.3b538bd8affected
Red HatRed Hat Enterprise Linux 8.6 Telecommunications Update Servicecontainer-tools:rhel8, 8060020250203202123.3b538bd8affected
Red HatRed Hat Enterprise Linux 8.6 Update Services for SAP Solutionscontainer-tools:rhel8, 8060020250203202123.3b538bd8affected
Red HatRed Hat Enterprise Linux 8.8 Extended Update Supportcontainer-tools:rhel8, 8080020250207173112.0f77c1b7affected
Red HatRed Hat Enterprise Linux 9podman, 4:5.2.2-13.el9_5affected
Red HatRed Hat Enterprise Linux 9buildah, 2:1.37.6-1.el9_5affected
Red HatRed Hat Enterprise Linux 9.0 Update Services for SAP Solutionspodman, 2:4.2.0-6.el9_0affected
Red HatRed Hat Enterprise Linux 9.0 Update Services for SAP Solutionsbuildah, 1:1.26.9-1.el9_0affected
Red HatRed Hat Enterprise Linux 9.2 Extended Update Supportbuildah, 1:1.29.5-1.el9_2affected
Red HatRed Hat Enterprise Linux 9.2 Extended Update Supportpodman, 2:4.4.1-22.el9_2affected
Red HatRed Hat Enterprise Linux 9.4 Extended Update Supportbuildah, 2:1.33.12-2.el9_4affected
Red HatRed Hat Enterprise Linux 9.4 Extended Update Supportpodman, 4:4.9.4-17.el9_4affected
Red HatRed Hat OpenShift Container Platform 4.12rhcos, 412.86.202503052321-0affected
Red HatRed Hat OpenShift Container Platform 4.12podman, 3:4.2.0-13.rhaos4.12.el9affected
Red HatRed Hat OpenShift Container Platform 4.13buildah, 1:1.29.5-1.rhaos4.13.el8affected
Red HatRed Hat OpenShift Container Platform 4.13podman, 3:4.4.1-16.rhaos4.13.el8affected
Red HatRed Hat OpenShift Container Platform 4.13rhcos, 413.92.202503112237-0affected
Red HatRed Hat OpenShift Container Platform 4.14podman, 3:4.4.1-22.rhaos4.14.el8affected
Red HatRed Hat OpenShift Container Platform 4.14buildah, 1:1.29.5-1.rhaos4.14.el8affected
Red HatRed Hat OpenShift Container Platform 4.14rhcos, 414.92.202503100617-0affected
Red HatRed Hat OpenShift Container Platform 4.14buildah, 1:1.29.5-1.rhaos4.14.el8affected
Red HatRed Hat OpenShift Container Platform 4.15podman, 3:4.4.1-33.rhaos4.15.el8affected
Red HatRed Hat OpenShift Container Platform 4.15buildah, 1:1.29.5-1.rhaos4.15.el8affected
Red HatRed Hat OpenShift Container Platform 4.15rhcos, 415.92.202503060749-0affected
Red HatRed Hat OpenShift Container Platform 4.15buildah, 1:1.29.5-1.rhaos4.15.el8affected
Red HatRed Hat OpenShift Container Platform 4.16podman, 4:4.9.4-13.rhaos4.16.el8affected
Red HatRed Hat OpenShift Container Platform 4.16buildah, 2:1.33.12-1.rhaos4.16.el8affected
Red HatRed Hat OpenShift Container Platform 4.16rhcos, 416.94.202502180249-0affected
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.

CWE-269 · source CWE mapping

Improper Privilege Management

Improper Privilege Management represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.