---
id: CVE-2024-1753
title: >-
  A flaw was found in Buildah (and subsequently Podman Build) which allows
  containers to mount arbitrary locations on the host filesystem into build
  containers
summary: >-
  A flaw was found in Buildah (and subsequently Podman Build) which allows
  containers to mount arbitrary locations on the host filesystem into build
  containers. A malicious Containerfile can use a dummy image with a symbolic
  link to the ro…
severity: high
cvss: 8.6
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'
cwe:
  - CWE-59
vendor: Red Hat
product: buildah
affected:
  - buildah 4.15.0
  - 'container-tools:4.0 (all versions)'
  - 'container-tools:rhel8 (all versions)'
  - 'container-tools:rhel8 (all versions)'
  - 'container-tools:rhel8 (all versions)'
  - 'container-tools:4.0 (all versions)'
  - 'container-tools:rhel8 (all versions)'
  - buildah (all versions)
  - podman (all versions)
  - buildah (all versions)
  - podman (all versions)
  - buildah (all versions)
  - podman (all versions)
  - podman (all versions)
  - podman (all versions)
  - podman (all versions)
  - podman (all versions)
  - podman (all versions)
  - buildah
  - podman
  - podman
patched:
  - github.com/containers/podman/v4 4.9.4
  - github.com/containers/podman/v5 5.0.1
published: '2024-03-18'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T00:16:56.820'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-1753'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2024:2049'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:2055'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:2064'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:2066'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:2077'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:2084'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:2089'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:2090'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:2097'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:2098'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:2548'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:2645'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:2669'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:2672'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:2784'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:2877'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:3254'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2024-1753'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2265513'
    label: secalert@redhat.com
  - url: >-
      https://github.com/containers/buildah/security/advisories/GHSA-pmf3-c36m-g5cf
    label: secalert@redhat.com
  - url: >-
      https://github.com/containers/podman/security/advisories/GHSA-874v-pj72-92f3
    label: secalert@redhat.com
  - url: 'https://pkg.go.dev/vuln/GO-2024-2658'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:2049'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:2055'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:2064'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:2066'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:2077'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:2084'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:2089'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:2090'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:2097'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:2098'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:2548'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:2645'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:2669'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:2672'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:2784'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:2877'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:3254'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/security/cve/CVE-2024-1753'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2265513'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://github.com/containers/buildah/security/advisories/GHSA-pmf3-c36m-g5cf
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://github.com/containers/podman/security/advisories/GHSA-874v-pj72-92f3
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FCRZVUDOFM5CPREQKBEU2VK2QK62PSBP/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KOYMVMQ7RWMDTSKQTBO734BE3WQPI2AJ/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZVBSVZGVABPYIHK5HZM472NPGWMI7WXH/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2024-1753'
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZVBSVZGVABPYIHK5HZM472NPGWMI7WXH
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KOYMVMQ7RWMDTSKQTBO734BE3WQPI2AJ
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FCRZVUDOFM5CPREQKBEU2VK2QK62PSBP
  - url: 'https://github.com/containers/podman'
tags:
  - nvd
  - cve.org
  - exploit-available
  - osv
  - go
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: total
  timestamp: '2024-05-02T15:05:28.144862Z'
epss: 0.0049
epssPercentile: 0.39492
aliases:
  - GHSA-874v-pj72-92f3
  - GHSA-pmf3-c36m-g5cf
  - GO-2024-2658
ecosystem: go
ingestedAt: '2026-09-12T03:13:01.766Z'
---

## Overview

A flaw was found in Buildah (and subsequently Podman Build) which allows containers to mount arbitrary locations on the host filesystem into build containers. A malicious Containerfile can use a dummy image with a symbolic link to the root filesystem as a mount source and cause the mount operation to mount the host root filesystem inside the RUN step. The commands inside the RUN step will then have read-write access to the host filesystem, allowing for full container escape at build time.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2024-1753)

Affected packages:

- `github.com/containers/podman/v4 < 4.9.4`
- `github.com/containers/podman/v5 < 5.0.1`

Patched in:

- `github.com/containers/podman/v4 4.9.4`
- `github.com/containers/podman/v5 5.0.1`

Source: https://osv.dev/vulnerability/GHSA-874v-pj72-92f3
