The vendor explicitly identifies these products as affected by this CVE.
- rhcertification/redhat-certification-system-ai-10 as a component of Red Hat Certification Program for Red Hat Enterprise Linux 9
- buildah as a component of Red Hat Enterprise Linux 10
- buildah-tests as a component of Red Hat Enterprise Linux 10
- buildah.src as a component of Red Hat Enterprise Linux 10
- podman as a component of Red Hat Enterprise Linux 10
- podman-docker as a component of Red Hat Enterprise Linux 10
- podman-remote as a component of Red Hat Enterprise Linux 10
- podman-tests as a component of Red Hat Enterprise Linux 10
- podman.src as a component of Red Hat Enterprise Linux 10
- buildah as a component of Red Hat Enterprise Linux 9
- buildah-tests as a component of Red Hat Enterprise Linux 9
- buildah.src as a component of Red Hat Enterprise Linux 9
- Summary
- A flaw was found in Buildah. Insecure handling of temporary directories and symlinks during the image build process, specifically within `TempDirForURL`, `downloadToDirectory`, and `stdinToDirectory` functions, allows a malicious server supplying a Git repository or tar archive to cause files outside the build context directory to be included or copied into the build. This could lead to a build breakout, enabling an attacker to manipulate files on the host system.
- Remediation
- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
