A vulnerability was found in `podman build` and `buildah.` This issue occurs in a container breakout by using --jobs=2 and a race condition when building a malicious Containerfile. SELinux might mitigate it, but even with SELinux on, it still allows the enumeration of files and directories on the host.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| github.com/containers/buildah(Go) | 1.38.0 | 1.38.1 | N/A |
| github.com/containers/buildah(Go) | 1.37.0 | 1.37.6 | N/A |
| github.com/containers/buildah(Go) | 1.35.0 | 1.35.5 | N/A |
| github.com/containers/buildah(Go) | 0 | 1.33.12 | N/A |
CVSS Metrics