<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 04:55:49 +0000</lastBuildDate>
    <item>
      <title>ALSA-2024:8846 — Important: container-tools:rhel8 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2024:8846</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: aardvark-dns, AlmaLinux:8: buildah, AlmaLinux:8: buildah-tests, AlmaLinux:8: cockpit-podman, AlmaLinux:8: conmon, AlmaLinux:8: container-selinux, AlmaLinux:8: containernetworking-plugins, AlmaLinux:8: containers-common, AlmaLinux:8: crit, AlmaLinux:8: criu and 24 more&lt;/p&gt;
&lt;p&gt;The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* Podman: Buildah: cri-o: FIPS Crypto-Policy Directory Mounting Issue in containers/common Go Library (CVE-2024-9341)
  * Buildah: Podman: Improper Input Validation in bind-propagation Option of Dockerfile RUN --mount Instruction (CVE-2024-9407)
  * buildah: Buildah allows arbitrary directory mount (CVE-2024-9675)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: aardvark-dns, AlmaLinux:8: buildah, AlmaLinux:8: buildah-tests, AlmaLinux:8: cockpit-podman, AlmaLinux:8: conmon, AlmaLinux:8: container-selinux, AlmaLinux:8: containernetworking-plugins, AlmaLinux:8: containers-common, AlmaLinux:8: crit, AlmaLinux:8: criu and 24 more&lt;/p&gt;
&lt;p&gt;The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* Podman: Buildah: cri-o: FIPS Crypto-Policy Directory Mounting Issue in containers/common Go Library (CVE-2024-9341)
  * Buildah: Podman: Improper Input Validation in bind-propagation Option of Dockerfile RUN --mount Instruction (CVE-2024-9407)
  * buildah: Buildah allows arbitrary directory mount (CVE-2024-9675)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2024:8846</guid>
    </item>
    <item>
      <title>bdu:2024-09460</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-09460</link>
      <description>bdu:2024-09460</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-09460</guid>
    </item>
    <item>
      <title>BELL-CVE-2024-9407</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2024-9407</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: buildah, Alpaquita:23: podman, Alpaquita:stream: buildah, Alpaquita:stream: containers-common, Alpaquita:stream: podman&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: buildah, Alpaquita:23: podman, Alpaquita:stream: buildah, Alpaquita:stream: containers-common, Alpaquita:stream: podman&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2024-9407</guid>
    </item>
    <item>
      <title>CLEANSTART-2024-AV70619 — vulnerability exists in the bind-propagation option of the Dockerfile RUN --mount instruction</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2024-av70619</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: buildah&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the buildah package. A vulnerability exists in the bind-propagation option of the Dockerfile RUN --mount instruction.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: buildah&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the buildah package. A vulnerability exists in the bind-propagation option of the Dockerfile RUN --mount instruction.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2024-av70619</guid>
    </item>
    <item>
      <title>EUVD-2026-276595</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-276595</link>
      <description>EUVD-2026-276595</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-276595</guid>
    </item>
    <item>
      <title>fkie_cve-2024-9407</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-9407</link>
      <description>&lt;p&gt;A vulnerability exists in the bind-propagation option of the Dockerfile RUN --mount instruction. The system does not properly validate the input passed to this option, allowing users to pass arbitrary parameters to the mount instruction. This issue can be exploited to mount sensitive directories from the host into a container during the build process and, in some cases, modify the contents of those mounted files. Even if SELinux is used, this vulnerability can bypass its protection by allowing the source directory to be relabeled to give the container access to host files.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability exists in the bind-propagation option of the Dockerfile RUN --mount instruction. The system does not properly validate the input passed to this option, allowing users to pass arbitrary parameters to the mount instruction. This issue can be exploited to mount sensitive directories from the host into a container during the build process and, in some cases, modify the contents of those mounted files. Even if SELinux is used, this vulnerability can bypass its protection by allowing the source directory to be relabeled to give the container access to host files.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-9407</guid>
    </item>
    <item>
      <title>GHSA-fhqq-8f65-5xfc — Improper Input Validation in Buildah and Podman</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-fhqq-8f65-5xfc</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/containers/buildah, Go: github.com/containers/podman/v5, Go: github.com/containers/podman, Go: github.com/containers/podman/v2, Go: github.com/containers/podman/v3, Go: github.com/containers/podman/v4&lt;/p&gt;
&lt;p&gt;A vulnerability exists in the bind-propagation option of the Dockerfile RUN --mount instruction. The system does not properly validate the input passed to this option, allowing users to pass arbitrary parameters to the mount instruction. This issue can be exploited to mount sensitive directories from the host into a container during the build process and, in some cases, modify the contents of those mounted files. Even if SELinux is used, this vulnerability can bypass its protection by allowing the source directory to be relabeled to give the container access to host files.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/containers/buildah, Go: github.com/containers/podman/v5, Go: github.com/containers/podman, Go: github.com/containers/podman/v2, Go: github.com/containers/podman/v3, Go: github.com/containers/podman/v4&lt;/p&gt;
&lt;p&gt;A vulnerability exists in the bind-propagation option of the Dockerfile RUN --mount instruction. The system does not properly validate the input passed to this option, allowing users to pass arbitrary parameters to the mount instruction. This issue can be exploited to mount sensitive directories from the host into a container during the build process and, in some cases, modify the contents of those mounted files. Even if SELinux is used, this vulnerability can bypass its protection by allowing the source directory to be relabeled to give the container access to host files.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-fhqq-8f65-5xfc</guid>
    </item>
    <item>
      <title>msrc_CVE-2024-9407 — Buildah: podman: improper input validation in bind-propagation option of dockerfile run --mount instruction</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2024-9407</link>
      <description>msrc_CVE-2024-9407</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2024-9407</guid>
    </item>
    <item>
      <title>OESA-2025-1053 — podman security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-1053</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: podman&lt;/p&gt;
&lt;p&gt;Podman manages the entire container ecosystem which includes pods, containers, container images, and container volumes using the libpod library.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and sends an invalid request over each stream that should solicit a stream of RST_STREAM frames from the peer. Depending on how the peer queues the RST_STREAM frames, this can consume excess memory, CPU, or both.(CVE-2019-9514)&#13;
&#13;
Uncontrolled recursion in the Parse functions in go/parser before Go 1.17.12 and Go 1.18.4 allow an attacker to cause a panic due to stack exhaustion via deeply nested types or declarations.(CVE-2022-1962)&#13;
&#13;
Requests forwarded by ReverseProxy include the raw query parameters from the inbound request, including unparsable parameters rejected by net/http. This could permit query parameter smuggling when a Go proxy forwards a parameter with an unparsable value. After fix, ReverseProxy sanitizes the query parameters in the forwarded query when the outbound request&amp;amp;apos;s Form field is set after the ReverseProxy. Director function returns, indicating that the proxy has parsed the query parameters. Proxies which do not parse query parameters continue to forward the original query parameters unchanged.(CVE-2022-2880)&#13;
&#13;
A too-short encoded message can cause a panic in Float.GobDecode and Rat GobDecode in math/big in Go before 1.17.13 and 1.18.5, p…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: podman&lt;/p&gt;
&lt;p&gt;Podman manages the entire container ecosystem which includes pods, containers, container images, and container volumes using the libpod library.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and sends an invalid request over each stream that should solicit a stream of RST_STREAM frames from the peer. Depending on how the peer queues the RST_STREAM frames, this can consume excess memory, CPU, or both.(CVE-2019-9514)&#13;
&#13;
Uncontrolled recursion in the Parse functions in go/parser before Go 1.17.12 and Go 1.18.4 allow an attacker to cause a panic due to stack exhaustion via deeply nested types or declarations.(CVE-2022-1962)&#13;
&#13;
Requests forwarded by ReverseProxy include the raw query parameters from the inbound request, including unparsable parameters rejected by net/http. This could permit query parameter smuggling when a Go proxy forwards a parameter with an unparsable value. After fix, ReverseProxy sanitizes the query parameters in the forwarded query when the outbound request&amp;amp;apos;s Form field is set after the ReverseProxy. Director function returns, indicating that the proxy has parsed the query parameters. Proxies which do not parse query parameters continue to forward the original query parameters unchanged.(CVE-2022-2880)&#13;
&#13;
A too-short encoded message can cause a panic in Float.GobDecode and Rat GobDecode in math/big in Go before 1.17.13 and 1.18.5, p…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-1053</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:0350-1 — Security update for govulncheck-vulndb</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:0350-1</link>
      <description>&lt;p&gt;Security update for govulncheck-vulndb&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for govulncheck-vulndb&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:0350-1</guid>
    </item>
    <item>
      <title>RHSA-2024:10147 — Red Hat Security Advisory: OpenShift Container Platform 4.16.24 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:10147</link>
      <description>&lt;p&gt;Podman: Buildah: cri-o: FIPS Crypto-Policy Directory Mounting Issue in containers/common Go Library Buildah: Podman: Improper Input Validation in bind-propagation Option of Dockerfile RUN --mount Instruction golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Podman: Buildah: cri-o: FIPS Crypto-Policy Directory Mounting Issue in containers/common Go Library Buildah: Podman: Improper Input Validation in bind-propagation Option of Dockerfile RUN --mount Instruction golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:10147</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:3545-1 — Security update for buildah</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:3545-1</link>
      <description>&lt;p&gt;Security update for buildah&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for buildah&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:3545-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-9407</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-9407</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: golang-github-containers-buildah, Ubuntu:Pro:24.04:LTS: golang-github-containers-buildah&lt;/p&gt;
&lt;p&gt;A vulnerability exists in the bind-propagation option of the Dockerfile RUN --mount instruction. The system does not properly validate the input passed to this option, allowing users to pass arbitrary parameters to the mount instruction. This issue can be exploited to mount sensitive directories from the host into a container during the build process and, in some cases, modify the contents of those mounted files. Even if SELinux is used, this vulnerability can bypass its protection by allowing the source directory to be relabeled to give the container access to host files.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: golang-github-containers-buildah, Ubuntu:Pro:24.04:LTS: golang-github-containers-buildah&lt;/p&gt;
&lt;p&gt;A vulnerability exists in the bind-propagation option of the Dockerfile RUN --mount instruction. The system does not properly validate the input passed to this option, allowing users to pass arbitrary parameters to the mount instruction. This issue can be exploited to mount sensitive directories from the host into a container during the build process and, in some cases, modify the contents of those mounted files. Even if SELinux is used, this vulnerability can bypass its protection by allowing the source directory to be relabeled to give the container access to host files.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-9407</guid>
    </item>
  </channel>
</rss>
