A flaw in the containers/common Go library, used by container runtimes such as Podman, Buildah, and CRI-O, allows a malicious container image to exploit the FIPS mode to bind mount arbitrary host directories into the container. The flaw arises from the MountsWithUIDGID() function, which attempts to mount a FIPS-related directory inside the container but does not properly verify the path. If the FIPS path is a symlink, it could point to arbitrary directories on the host, allowing an attacker to access sensitive host files.
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2024:8039 https://access.redhat.com/errata/RHSA-2024:8039
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2024:8112 https://access.redhat.com/errata/RHSA-2024:8112
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.17 Via RHSA-2024:7925 https://access.redhat.com/errata/RHSA-2024:7925
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.14 Via RHSA-2024:8238 https://access.redhat.com/errata/RHSA-2024:8238
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.16 Via RHSA-2024:8263 https://access.redhat.com/errata/RHSA-2024:8263
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.15 Via RHSA-2024:8428 https://access.redhat.com/errata/RHSA-2024:8428
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2024:8846 https://access.redhat.com/errata/RHSA-2024:8846
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.13 Via RHSA-2024:8690 https://access.redhat.com/errata/RHSA-2024:8690
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.12 Ironic content for Red Hat OpenShift Container Platform 4.12 Via RHSA-2024:8694 https://access.redhat.com/errata/RHSA-2024:8694
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2024:9454 https://access.redhat.com/errata/RHSA-2024:9454
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2024:9459 https://access.redhat.com/errata/RHSA-2024:9459
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.16 Via RHSA-2024:10147 https://access.redhat.com/errata/RHSA-2024:10147
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.17 Via RHSA-2024:10818 https://access.redhat.com/errata/RHSA-2024:10818