---
id: CVE-2024-9675
title: A vulnerability was found in Buildah
summary: >-
  A vulnerability was found in Buildah. Cache mounts do not properly validate
  that user-specified paths for the cache are within our cache directory,
  allowing a `RUN` instruction in a Container file to mount an arbitrary
  directory from the…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-22
vendor: buildah_project
product: buildah
affected:
  - buildah
  - openshift_container_platform = 4.13
  - openshift_container_platform = 4.14
  - openshift_container_platform = 4.15
  - openshift_container_platform = 4.16
  - openshift_container_platform = 4.17
  - enterprise_linux = 8.0
  - enterprise_linux = 9.0
  - enterprise_linux_eus = 8.8
  - enterprise_linux_eus = 9.0
  - enterprise_linux_eus = 9.2
  - enterprise_linux_eus = 9.4
  - enterprise_linux_for_arm_64 = 8.0_aarch64
  - enterprise_linux_for_arm_64 = 9.0_aarch64
  - enterprise_linux_for_arm_64_eus = 8.8_aarch64
  - enterprise_linux_for_arm_64_eus = 9.0_aarch64
  - enterprise_linux_for_arm_64_eus = 9.2_aarch64
  - enterprise_linux_for_arm_64_eus = 9.4_aarch64
  - enterprise_linux_for_ibm_z_systems = 8.0_s390x
  - enterprise_linux_for_ibm_z_systems = 9.0_s390x
  - enterprise_linux_for_ibm_z_systems_eus = 8.8_s390x
  - enterprise_linux_for_ibm_z_systems_eus = 9.0_s390x
  - enterprise_linux_for_ibm_z_systems_eus = 9.2_s390x
  - enterprise_linux_for_ibm_z_systems_eus = 9.4_s390x
  - enterprise_linux_for_power_little_endian = 8.0_ppc64le
  - enterprise_linux_for_power_little_endian = 9.0_ppc64le
  - enterprise_linux_for_power_little_endian_eus = 8.8_ppc64le
  - enterprise_linux_for_power_little_endian_eus = 9.0_ppc64le
  - enterprise_linux_for_power_little_endian_eus = 9.2_ppc64le
  - enterprise_linux_for_power_little_endian_eus = 9.4_ppc64le
  - enterprise_linux_server_aus = 8.6
  - enterprise_linux_server_aus = 9.2
  - enterprise_linux_server_aus = 9.4
  - >-
    enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions
    = 8.6_ppc64le
  - >-
    enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions
    = 8.8_ppc64le
  - >-
    enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions
    = 9.0_ppc64le
  - >-
    enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions
    = 9.2_ppc64le
  - >-
    enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions
    = 9.4_ppc64le
  - enterprise_linux_server_tus = 8.6
  - enterprise_linux_server_tus = 8.8
  - enterprise_linux_update_services_for_sap_solutions = 8.6
  - enterprise_linux_update_services_for_sap_solutions = 8.8
  - enterprise_linux_update_services_for_sap_solutions = 9.0
  - enterprise_linux_update_services_for_sap_solutions = 9.2
  - enterprise_linux_update_services_for_sap_solutions = 9.4
published: '2024-10-09'
updated: '2026-06-25'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-9675'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2024:8563'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:8675'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:8679'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:8686'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:8690'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:8700'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:8703'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:8707'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:8708'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:8709'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:8846'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:8984'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:8994'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:9051'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:9454'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:9459'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:2445'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:2449'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:2454'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:2701'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:2710'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:3301'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:3573'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2024-9675'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2317458'
    label: secalert@redhat.com
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2024-9675'
  - url: >-
      https://github.com/containers/buildah/commit/aa67e5d71ee7ec07122a210baa3b13966a9e086c
  - url: 'https://pkg.go.dev/vuln/GO-2024-3186'
  - url: 'https://github.com/containers/buildah'
  - url: 'https://access.redhat.com/errata/RHBA-2024:10967'
tags:
  - nvd
  - osv
  - go
  - score-dispute
epss: 0.00392
epssPercentile: 0.33137
ingestedAt: '2026-06-29T13:24:33.968Z'
aliases:
  - GHSA-586p-749j-fhwp
  - GO-2024-3186
ecosystem: go
patched:
  - github.com/containers/buildah 1.38.0
scores:
  nvd: 7.8
  osv: 4.4
---

## Overview

A vulnerability was found in Buildah. Cache mounts do not properly validate that user-specified paths for the cache are within our cache directory, allowing a `RUN` instruction in a Container file to mount an arbitrary directory from the host (read/write) into the container as long as those files can be accessed by the user running Buildah.

## Affected

- `buildah`
- `openshift_container_platform = 4.13`
- `openshift_container_platform = 4.14`
- `openshift_container_platform = 4.15`
- `openshift_container_platform = 4.16`
- `openshift_container_platform = 4.17`
- `enterprise_linux = 8.0`
- `enterprise_linux = 9.0`
- `enterprise_linux_eus = 8.8`
- `enterprise_linux_eus = 9.0`
- `enterprise_linux_eus = 9.2`
- `enterprise_linux_eus = 9.4`
- `enterprise_linux_for_arm_64 = 8.0_aarch64`
- `enterprise_linux_for_arm_64 = 9.0_aarch64`
- `enterprise_linux_for_arm_64_eus = 8.8_aarch64`
- `enterprise_linux_for_arm_64_eus = 9.0_aarch64`
- `enterprise_linux_for_arm_64_eus = 9.2_aarch64`
- `enterprise_linux_for_arm_64_eus = 9.4_aarch64`
- `enterprise_linux_for_ibm_z_systems = 8.0_s390x`
- `enterprise_linux_for_ibm_z_systems = 9.0_s390x`
- `enterprise_linux_for_ibm_z_systems_eus = 8.8_s390x`
- `enterprise_linux_for_ibm_z_systems_eus = 9.0_s390x`
- `enterprise_linux_for_ibm_z_systems_eus = 9.2_s390x`
- `enterprise_linux_for_ibm_z_systems_eus = 9.4_s390x`
- `enterprise_linux_for_power_little_endian = 8.0_ppc64le`
- `enterprise_linux_for_power_little_endian = 9.0_ppc64le`
- `enterprise_linux_for_power_little_endian_eus = 8.8_ppc64le`
- `enterprise_linux_for_power_little_endian_eus = 9.0_ppc64le`
- `enterprise_linux_for_power_little_endian_eus = 9.2_ppc64le`
- `enterprise_linux_for_power_little_endian_eus = 9.4_ppc64le`
- `enterprise_linux_server_aus = 8.6`
- `enterprise_linux_server_aus = 9.2`
- `enterprise_linux_server_aus = 9.4`
- `enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions = 8.6_ppc64le`
- `enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions = 8.8_ppc64le`
- `enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions = 9.0_ppc64le`
- `enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions = 9.2_ppc64le`
- `enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions = 9.4_ppc64le`
- `enterprise_linux_server_tus = 8.6`
- `enterprise_linux_server_tus = 8.8`
- `enterprise_linux_update_services_for_sap_solutions = 8.6`
- `enterprise_linux_update_services_for_sap_solutions = 8.8`
- `enterprise_linux_update_services_for_sap_solutions = 9.0`
- `enterprise_linux_update_services_for_sap_solutions = 9.2`
- `enterprise_linux_update_services_for_sap_solutions = 9.4`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2024-9675)

Affected packages:

- `github.com/containers/buildah < 1.38.0`

Patched in:

- `github.com/containers/buildah 1.38.0`

Source: https://osv.dev/vulnerability/GHSA-586p-749j-fhwp
