Source: golang-github-containers-common
X-Debbugs-CC: t...@security.debian.org
Severity: important
Tags: security

Hi,

The following vulnerability was published for golang-github-containers-common.

CVE-2024-9341[0]:
| A flaw was found in Go. When FIPS mode is enabled on a system,
| container runtimes may incorrectly handle certain file paths due to
| improper validation in the containers/common Go library. This flaw
| allows an attacker to exploit symbolic links and trick the system
| into mounting sensitive host directories inside a container. This
| issue also allows attackers to access critical host files, bypassing
| the intended isolation between containers and the host system.

https://bugzilla.redhat.com/show_bug.cgi?id=2315691


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2024-9341
    https://www.cve.org/CVERecord?id=CVE-2024-9341

Please adjust the affected versions in the BTS as needed.

Reply via email to