{"id":"CVE-2024-1753","aliases":["GHSA-874v-pj72-92f3","GHSA-pmf3-c36m-g5cf","GO-2024-2658"],"url":"https://o3.security/vulnerability/CVE-2024-1753","summary":"Podman affected by CVE-2024-1753 container escape at build time ","details":"A flaw was found in Buildah (and subsequently Podman Build) which allows containers to mount arbitrary locations on the host filesystem into build containers. A malicious Containerfile can use a dummy image with a symbolic link to the root filesystem as a mount source and cause the mount operation to mount the host root filesystem inside the RUN step. The commands inside the RUN step will then have read-write access to the host filesystem, allowing for full container escape at build time.","published":"2024-03-18T15:15:41.170Z","modified":"2026-04-16T04:31:28.580641879Z","cvss":{"score":8.6,"severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"},"epss":{"score":0.0049,"percentile":0.41039,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/containers/podman/v4","fixedVersion":"4.9.4"},{"ecosystem":"Go","name":"github.com/containers/podman/v5","fixedVersion":"5.0.1"}],"fix":null,"references":[{"type":"WEB","url":"https://pkg.go.dev/vuln/GO-2024-2658"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KOYMVMQ7RWMDTSKQTBO734BE3WQPI2AJ/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FCRZVUDOFM5CPREQKBEU2VK2QK62PSBP/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZVBSVZGVABPYIHK5HZM472NPGWMI7WXH/"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2024-1753"},{"type":"ADVISORY","url":"https://github.com/containers/podman/security/advisories/GHSA-874v-pj72-92f3"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2024:2089"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2024:2098"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2024:2064"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2024:2066"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2024:2672"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2024:3254"},{"type":"ADVISORY","url":"https://github.com/containers/buildah/security/advisories/GHSA-pmf3-c36m-g5cf"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2024:2049"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2024:2084"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2024:2097"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2024:2548"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2024:2669"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2024:2055"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2024:2077"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2024:2090"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2024:2645"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2024:2784"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2024:2877"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2265513"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-04-16T04:31:28.580641879Z"}}