Red Hat released Important security updates for Red Hat OpenShift Container Platform and RHEL 9 Podman and Buildah deployments to remediate container-stack vulnerabilities, notably CVE-2024-9675 and CVE-2024-9676. CVE-2024-9675 can permit arbitrary directory mounts through Buildah, while CVE-2024-9676 is a containers/storage symlink-traversal flaw affecting Podman, Buildah, and CRI-O. When a malicious image runs with automatically assigned user namespaces, the latter can cause container creation to block indefinitely or CRI-O to exhaust memory and crash; limited error-message disclosure is also possible to the user operating the affected software.
Affected OpenShift releases include 4.12, 4.13, 4.14, 4.15, 4.16, 4.17, and 4.18, with related advisories also addressing flaws such as Dockerfile bind-propagation validation, FIPS crypto-policy mounting, Distribution JWT signing-key injection, and denial-of-service issues in Go, BIND, libxml2, GRUB2, and the Linux kernel. Red Hat advises OpenShift customers to update clusters through their supported release channels using the CLI or web console, and RHEL 9 users to deploy the updated Podman or Buildah packages for their supported architecture and subscription channel.

See real exploitation activity before you spend the cycle.
21 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2025:3573, making OpenShift Container Platform 4.12.75 available as an Important security update. The release addressed flaws in Buildah, golang.org/x/net/html, the Linux kernel USB-audio subsystem, libxml2, and GRUB2.
Red Hat issued RHSA-2025:3301, an Important advisory releasing OpenShift Container Platform 4.16.38. The update fixed vulnerabilities in Buildah, containers/storage, the Linux kernel, libxml2, GRUB2, Moby, and go-jose.
Red Hat issued RHSA-2025:2710, an Important advisory releasing OpenShift Container Platform 4.14.49. The update remediated vulnerabilities affecting Buildah, Podman, CRI-O, runc, BIND, the Linux kernel, and golang.org/x/net/html, including container-breakout and denial-of-service risks.
Red Hat issued Important advisory RHSA-2025:2454 and released OpenShift Container Platform 4.15.47 images. The update addressed Buildah and Podman container flaws, containers/storage symlink traversal, BIND CPU exhaustion, and a Linux kernel HID issue.
Red Hat issued RHSA-2025:2445, an Important advisory for OpenShift Container Platform 4.17.20. It addressed CVE-2024-9675, the Linux kernel HID report-buffer initialization flaw, and Distribution JWT token-authentication signing-key injection.
Red Hat issued RHSA-2025:2449, an Important advisory releasing OpenShift Container Platform 4.18.4. The update fixed Buildah arbitrary directory mounting, mholt/archiver path traversal, a Distribution JWT signing-key injection flaw, and other listed vulnerabilities.
Red Hat released RHSA-2024:10289 for the RHEL 8 container-tools:rhel8 module, remediating CVE-2024-9676. The containers/storage symlink-traversal flaw could allow a malicious image run with an automatically assigned user namespace to trigger a denial of service in Podman, Buildah, or CRI-O.
Red Hat issued Moderate-severity advisory RHSA-2024:9926 for RHEL 9.4 supported update channels, providing Buildah 1.33.11-1.el9_4. The update remediated CVE-2024-9407, involving Dockerfile RUN --mount bind-propagation validation, and the CVE-2024-9676 containers/storage symlink-traversal denial-of-service flaw.
Red Hat issued Important-security advisory RHSA-2024:8994 for OpenShift Container Platform 4.15.38. The update remediated CVE-2024-9675, a Buildah flaw allowing arbitrary directory mounting, for supported deployments on RHEL 8 and RHEL 9.
Red Hat issued Important advisory RHSA-2024:8984 for OpenShift Container Platform 4.17.4. The update remediated Buildah arbitrary-directory mounting vulnerability CVE-2024-9675 and the containers/storage symlink-traversal denial-of-service flaw CVE-2024-9676 affecting Podman, Buildah, and CRI-O.
Red Hat issued RHSA-2024:9454, an Important advisory delivering Podman 5.2.2-9.el9_5 for RHEL 9. It remediated Go stack-exhaustion vulnerabilities, container mount-validation issues, and the CVE-2024-9676 symlink-traversal denial-of-service flaw.
Red Hat issued RHSA-2024:9459, providing Buildah 1.37.5-1.el9_5 for RHEL 9. The Important update fixed Go stack-exhaustion issues, container mount-validation flaws, CVE-2024-9675, and CVE-2024-9676.
Red Hat issued RHSA-2024:9051, an Important RHEL 9 Podman update delivering Podman 4.9.4-16.el9_4. It fixed mount-validation flaws CVE-2024-9407 and CVE-2024-9675 and the containers/storage symlink-traversal DoS vulnerability CVE-2024-9676.
Red Hat issued Important advisory RHSA-2024:8700, releasing OpenShift Container Platform 4.14.40 packages and updates. It fixed Buildah arbitrary-directory mounting (CVE-2024-9675), containers/storage symlink traversal (CVE-2024-9676), and three Go stack-exhaustion vulnerabilities.
Red Hat issued Important advisory RHSA-2024:8686 for OpenShift Container Platform 4.16.20. It remediated Buildah arbitrary-directory mounting (CVE-2024-9675) and the containers/storage symlink-traversal denial-of-service flaw (CVE-2024-9676).
Red Hat issued RHSA-2024:8690, an Important advisory providing OpenShift Container Platform 4.13.53 images and packages. The update remediated CVE-2024-9675 and CVE-2024-9676, along with FIPS mount and Go stack-exhaustion flaws.
Red Hat issued Important advisory RHSA-2024:8846 for the container-tools:rhel8 module, updating Podman, Buildah, containers-common, and runc. The update remediated CVE-2024-9341, CVE-2024-9407, and CVE-2024-9675 for supported RHEL 8 and RHEL 8.10 Extended Life Cycle systems.
Red Hat issued Moderate-severity advisory RHSA-2024:8418 for OpenShift Container Platform 4.16, making version 4.16.19 available. The update remediated CVE-2024-5569 in jaraco/zipp, the CVE-2024-9676 containers/storage symlink-traversal denial-of-service flaw, and CVE-2024-24790 in Go net/netip.
Red Hat issued Moderate-severity advisory RHSA-2024:8437 for OpenShift Container Platform 4.17.3. The update remediated CVE-2024-9676, a containers/storage symlink-traversal vulnerability affecting Podman, Buildah, and CRI-O that could cause denial of service.
Red Hat's bug record for CVE-2024-9407 was reported. The improper input-validation flaw in Buildah and Podman could let an attacker with build privileges pass arbitrary bind-propagation parameters, mount host files into a build container, and potentially modify them.
Red Hat documented CVE-2024-9341 in containers/common, where MountsWithUIDGID() inadequately validates a FIPS-related mount path. A malicious container image can use a symlink to redirect the mount to an arbitrary host directory, potentially exposing sensitive host files.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
22 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.