Fedora 41: buildah 2025-908dfe95f6 Security Advisory Updates
Summary
The buildah package provides a command line tool which can be used to
* create a working container from scratch
or
* create a working container from an image as a starting point
* mount/umount a working container's root file system for manipulation
* save container's root file system layer to create a new image
* delete a working container or an image
Update Information:
Security fix for CVE-2024-11218 - fixed in buildah 1.38.1, podman 5.3.2
Automatic update for buildah-1.38.1-1.fc41, containers-common-0.61.1-1.fc41,
podman-5.3.2-1.fc41.
Changelog for buildah
* Tue Jan 21 2025 Packit
Change Log
* Tue Jan 21 2025 Packit
References
[ 1 ] Bug #2326231 - CVE-2024-11218 podman: buildah: Container breakout by using --jobs=2 and a race condition when building a malicious Containerfile
https://bugzilla.redhat.com/show_bug.cgi?id=2326231
Update Instructions
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-908dfe95f6' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label