• CVE-2024-9341

发布时间: 2025年1月17日

修改时间: 2025年1月17日

概要

A flaw was found in Go. When FIPS mode is enabled on a system, container runtimes may incorrectly handle certain file paths due to improper validation in the containers/common Go library. This flaw allows an attacker to exploit symbolic links and trick the system into mounting sensitive host directories inside a container. This issue also allows attackers to access critical host files, bypassing the intended isolation between containers and the host system.

CVSS v3 指标

NVD openEuler
Confidentiality High High
Attack Vector Network Network
CVSS评分 8.2 8.2
Attack Complexity Low Low
Privileges Required None None
Scope Changed Changed
Integrity Low Low
User Interaction Required Required
Availability None None

安全公告

公告名 概要 发布时间
KylinSec-SA-2025-1606 podman security update 2025年3月18日

影响产品

产品 状态
V6 podman Fixed