BuildKit possible host system access from mount stub cleaner
Published Jan 31, 2024
10.0
CRITICALCVSS 3.1
EPSS 2.46%
Description
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. A malicious BuildKit frontend or Dockerfile using RUN --mount could trick the feature that removes empty files created for the mountpoints into removing a file outside the container, from the host system. The issue has been fixed in v0.12.5. Workarounds include avoiding using BuildKit frontends from an untrusted source or building an untrusted Dockerfile containing RUN --mount feature.
Affected products
-
- Version < 0.12.5StatusaffectedConstraints-
- Version
- < 0.12.5
No data.
No Red Hat product state for this CVE.
github.com/moby/buildkit
Go
Introduced 0 Fixed 0.12.5
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/moby/buildkit | 0 | 0.12.5 |
Remediation
Red Hat statement
The following are preconditions for exploiting this vulnerability: * A container is built using a Dockerfile OR * A BuildKit frontend is invoked with the RUN --mount command Additionally, for the cleanup operations to impact the host file system the parent of the target directory needs to be replaced with a symbolic link during the build container's lifetime. For these reasons, this flaw was rated with an important severity.
References (10)
- https://access.redhat.com/security/cve/CVE-2024-23652 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2262225 Issue Tracking
- https://github.com/advisories/GHSA-4v98-7qmw-rqr8 Advisory
- https://github.com/moby/buildkit/pull/4603 x_refsource_MISCPatchVendor Advisory
- https://github.com/moby/buildkit/releases/tag/v0.12.5 x_refsource_MISCPatchRelease Notes
- https://github.com/moby/buildkit/security/advisories/GHSA-4v98-7qmw-rqr8 x_refsource_CONFIRMVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-23652
- https://pkg.go.dev/vuln/GO-2024-2494
- https://snyk.io/blog/cve-2024-23652-buildkit-build-time-container-teardown-arbitrary-delete/
- https://www.cve.org/CVERecord?id=CVE-2024-23652
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2024-23652 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2262225 | Issue Tracking | |
| https://github.com/advisories/GHSA-4v98-7qmw-rqr8 | Advisory | |
| https://github.com/moby/buildkit/pull/4603 | x_refsource_MISCPatchVendor Advisory | |
| https://github.com/moby/buildkit/releases/tag/v0.12.5 | x_refsource_MISCPatchRelease Notes | |
| https://github.com/moby/buildkit/security/advisories/GHSA-4v98-7qmw-rqr8 | x_refsource_CONFIRMVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2024-23652 | ||
| https://pkg.go.dev/vuln/GO-2024-2494 | ||
| https://snyk.io/blog/cve-2024-23652-buildkit-build-time-container-teardown-arbitrary-delete/ | ||
| https://www.cve.org/CVERecord?id=CVE-2024-23652 |
Change history (0)
No recorded changes yet.