Bug 2521191 (CVE-2026-44517) - CVE-2026-44517 github.com/containers/buildah: Buildah: Build breakout via malicious Git repository or tar archive
Summary: CVE-2026-44517 github.com/containers/buildah: Buildah: Build breakout via mal...
Keywords:
Status: NEW
Alias: CVE-2026-44517
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-08-21 20:48 UTC by OSIDB Bzimport
Modified: 2026-08-24 18:34 UTC (History)
16 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-08-21 20:48:33 UTC
Buildah is a tool that facilitates building OCI images. From 1.38.1 until 1.43.2 and 1.44.0, TempDirForURL in define/types.go does not securely confine Git repository subdirectories to the downloaded build context, and downloadToDirectory and stdinToDirectory can follow a Dockerfile symlink left by a partially extracted tar archive. A malicious server supplying a Git repository or tar archive can cause files outside the build context directory to be included in the context or copied into the build. This issue is fixed in versions 1.43.2 and 1.44.0.


Note You need to log in before you can comment on or make changes to this bug.