Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:0923 - Security Advisory
Issued:
2025-02-04
Updated:
2025-02-04

RHSA-2025:0923 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: buildah security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for buildah is now available for Red Hat Enterprise Linux 9.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The buildah package provides a tool for facilitating building OCI container images. Among other things, buildah enables you to: Create a working container, either from scratch or using an image as a starting point; Create an image, either from a working container or using the instructions in a Dockerfile; Build both Docker and OCI images.

Security Fix(es):

  • podman: buildah: Container breakout by using --jobs=2 and a race condition when building a malicious Containerfile (CVE-2024-11218)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 9 x86_64
  • Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.6 x86_64
  • Red Hat Enterprise Linux Server - AUS 9.6 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 9 s390x
  • Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.6 s390x
  • Red Hat Enterprise Linux for Power, little endian 9 ppc64le
  • Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.6 ppc64le
  • Red Hat Enterprise Linux for ARM 64 9 aarch64
  • Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.6 aarch64
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.6 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.6 x86_64
  • Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.6 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.6 s390x

Fixes

  • BZ - 2326231 - CVE-2024-11218 podman: buildah: Container breakout by using --jobs=2 and a race condition when building a malicious Containerfile

CVEs

  • CVE-2024-11218

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 9

SRPM
buildah-1.37.6-1.el9_5.src.rpm SHA-256: 173a223df8a68fdc1f70b3cd8f14bf0e14d66176792877f635296111fe0df75e
x86_64
buildah-1.37.6-1.el9_5.x86_64.rpm SHA-256: 48118ef2ed4f4c1d44223f2364d651e8fa46a4407f9879f4e1559eac2ab8ffaf
buildah-debuginfo-1.37.6-1.el9_5.x86_64.rpm SHA-256: 9a8810c2be5088468fd1dcd65010976d1218330dee025d31d788bda06ac3425b
buildah-debugsource-1.37.6-1.el9_5.x86_64.rpm SHA-256: 14b56d0810ccd05138c5a24475d8eec358865a7164dc48a422f43087df69d26e
buildah-tests-1.37.6-1.el9_5.x86_64.rpm SHA-256: e1ebc89443428f7a85a793d0cb793da1cab7aacf66b9abf833d9f4d1fb8d670b
buildah-tests-debuginfo-1.37.6-1.el9_5.x86_64.rpm SHA-256: 2e716d5c7e6af7fff071be5be17da9df2cfb505ed1cde6ba169b1c9ec271ac4e

Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.6

SRPM
buildah-1.37.6-1.el9_5.src.rpm SHA-256: 173a223df8a68fdc1f70b3cd8f14bf0e14d66176792877f635296111fe0df75e
x86_64
buildah-1.37.6-1.el9_5.x86_64.rpm SHA-256: 48118ef2ed4f4c1d44223f2364d651e8fa46a4407f9879f4e1559eac2ab8ffaf
buildah-debuginfo-1.37.6-1.el9_5.x86_64.rpm SHA-256: 9a8810c2be5088468fd1dcd65010976d1218330dee025d31d788bda06ac3425b
buildah-debugsource-1.37.6-1.el9_5.x86_64.rpm SHA-256: 14b56d0810ccd05138c5a24475d8eec358865a7164dc48a422f43087df69d26e
buildah-tests-1.37.6-1.el9_5.x86_64.rpm SHA-256: e1ebc89443428f7a85a793d0cb793da1cab7aacf66b9abf833d9f4d1fb8d670b
buildah-tests-debuginfo-1.37.6-1.el9_5.x86_64.rpm SHA-256: 2e716d5c7e6af7fff071be5be17da9df2cfb505ed1cde6ba169b1c9ec271ac4e

Red Hat Enterprise Linux Server - AUS 9.6

SRPM
buildah-1.37.6-1.el9_5.src.rpm SHA-256: 173a223df8a68fdc1f70b3cd8f14bf0e14d66176792877f635296111fe0df75e
x86_64
buildah-1.37.6-1.el9_5.x86_64.rpm SHA-256: 48118ef2ed4f4c1d44223f2364d651e8fa46a4407f9879f4e1559eac2ab8ffaf
buildah-debuginfo-1.37.6-1.el9_5.x86_64.rpm SHA-256: 9a8810c2be5088468fd1dcd65010976d1218330dee025d31d788bda06ac3425b
buildah-debugsource-1.37.6-1.el9_5.x86_64.rpm SHA-256: 14b56d0810ccd05138c5a24475d8eec358865a7164dc48a422f43087df69d26e
buildah-tests-1.37.6-1.el9_5.x86_64.rpm SHA-256: e1ebc89443428f7a85a793d0cb793da1cab7aacf66b9abf833d9f4d1fb8d670b
buildah-tests-debuginfo-1.37.6-1.el9_5.x86_64.rpm SHA-256: 2e716d5c7e6af7fff071be5be17da9df2cfb505ed1cde6ba169b1c9ec271ac4e

Red Hat Enterprise Linux for IBM z Systems 9

SRPM
buildah-1.37.6-1.el9_5.src.rpm SHA-256: 173a223df8a68fdc1f70b3cd8f14bf0e14d66176792877f635296111fe0df75e
s390x
buildah-1.37.6-1.el9_5.s390x.rpm SHA-256: b1e61fc1ab06c1be20ba7cad809986e3931890cc86e2fb2aae7e22ec0f35d62a
buildah-debuginfo-1.37.6-1.el9_5.s390x.rpm SHA-256: ea28b4bccc7628d0e0882fa75c35d47bb8aba4179162701faacce1644ed8371c
buildah-debugsource-1.37.6-1.el9_5.s390x.rpm SHA-256: 69206debe10a76eaf1f2bd04150784940021bf19d026e08e9dd7f7a19f80ab14
buildah-tests-1.37.6-1.el9_5.s390x.rpm SHA-256: 8a39d6785390ffbd25aa891498d671757884e0712915f894434e53eabde8bbd7
buildah-tests-debuginfo-1.37.6-1.el9_5.s390x.rpm SHA-256: 0fa61f62fac85d274aa6e642a95d3484c741d9bb1a224a0596827cf59fc55209

Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.6

SRPM
buildah-1.37.6-1.el9_5.src.rpm SHA-256: 173a223df8a68fdc1f70b3cd8f14bf0e14d66176792877f635296111fe0df75e
s390x
buildah-1.37.6-1.el9_5.s390x.rpm SHA-256: b1e61fc1ab06c1be20ba7cad809986e3931890cc86e2fb2aae7e22ec0f35d62a
buildah-debuginfo-1.37.6-1.el9_5.s390x.rpm SHA-256: ea28b4bccc7628d0e0882fa75c35d47bb8aba4179162701faacce1644ed8371c
buildah-debugsource-1.37.6-1.el9_5.s390x.rpm SHA-256: 69206debe10a76eaf1f2bd04150784940021bf19d026e08e9dd7f7a19f80ab14
buildah-tests-1.37.6-1.el9_5.s390x.rpm SHA-256: 8a39d6785390ffbd25aa891498d671757884e0712915f894434e53eabde8bbd7
buildah-tests-debuginfo-1.37.6-1.el9_5.s390x.rpm SHA-256: 0fa61f62fac85d274aa6e642a95d3484c741d9bb1a224a0596827cf59fc55209

Red Hat Enterprise Linux for Power, little endian 9

SRPM
buildah-1.37.6-1.el9_5.src.rpm SHA-256: 173a223df8a68fdc1f70b3cd8f14bf0e14d66176792877f635296111fe0df75e
ppc64le
buildah-1.37.6-1.el9_5.ppc64le.rpm SHA-256: ba2ca5a99c9401562110052ad1d06a1853df614763695c853587a723e4133982
buildah-debuginfo-1.37.6-1.el9_5.ppc64le.rpm SHA-256: 9d2ea290d8c40547be77a8f13249b8a53caff7d254771d17affcbf167941c89f
buildah-debugsource-1.37.6-1.el9_5.ppc64le.rpm SHA-256: ee4c2bcf4a5b0c5f3e083303fba01e4b2749b3f720ff7ac634b8d5734ce0941c
buildah-tests-1.37.6-1.el9_5.ppc64le.rpm SHA-256: eda5f19b1b4d32fd3a5abd2cdbaf9440e547d6e89dc373c8d82bb066914e740b
buildah-tests-debuginfo-1.37.6-1.el9_5.ppc64le.rpm SHA-256: 7848ef0eb7835e18d48a49c90dae7adf6df8ebf314126e2d80cfea02e815e7e6

Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.6

SRPM
buildah-1.37.6-1.el9_5.src.rpm SHA-256: 173a223df8a68fdc1f70b3cd8f14bf0e14d66176792877f635296111fe0df75e
ppc64le
buildah-1.37.6-1.el9_5.ppc64le.rpm SHA-256: ba2ca5a99c9401562110052ad1d06a1853df614763695c853587a723e4133982
buildah-debuginfo-1.37.6-1.el9_5.ppc64le.rpm SHA-256: 9d2ea290d8c40547be77a8f13249b8a53caff7d254771d17affcbf167941c89f
buildah-debugsource-1.37.6-1.el9_5.ppc64le.rpm SHA-256: ee4c2bcf4a5b0c5f3e083303fba01e4b2749b3f720ff7ac634b8d5734ce0941c
buildah-tests-1.37.6-1.el9_5.ppc64le.rpm SHA-256: eda5f19b1b4d32fd3a5abd2cdbaf9440e547d6e89dc373c8d82bb066914e740b
buildah-tests-debuginfo-1.37.6-1.el9_5.ppc64le.rpm SHA-256: 7848ef0eb7835e18d48a49c90dae7adf6df8ebf314126e2d80cfea02e815e7e6

Red Hat Enterprise Linux for ARM 64 9

SRPM
buildah-1.37.6-1.el9_5.src.rpm SHA-256: 173a223df8a68fdc1f70b3cd8f14bf0e14d66176792877f635296111fe0df75e
aarch64
buildah-1.37.6-1.el9_5.aarch64.rpm SHA-256: 6c8e5c00d79d11ceb09868c383eee806c3655413489b018bc0b64571b9dab8f8
buildah-debuginfo-1.37.6-1.el9_5.aarch64.rpm SHA-256: b1480617d5028f613eaaedfac34e8efecb37d0591b33caf880a7226765e8c11a
buildah-debugsource-1.37.6-1.el9_5.aarch64.rpm SHA-256: 7134c2aa70bb73d28190413de84a2bc2468ef56bfd9cb687c4b8e74a491a31ce
buildah-tests-1.37.6-1.el9_5.aarch64.rpm SHA-256: b5099a4e92fc7f05fdf4c57e8a620ef69a8cc90338aae1e04586b9a3b0d7b02c
buildah-tests-debuginfo-1.37.6-1.el9_5.aarch64.rpm SHA-256: ded78cdfbcbda96fae0849e4a28437b116b2501a5ce2a19dd104cad72a7a4c93

Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.6

SRPM
buildah-1.37.6-1.el9_5.src.rpm SHA-256: 173a223df8a68fdc1f70b3cd8f14bf0e14d66176792877f635296111fe0df75e
aarch64
buildah-1.37.6-1.el9_5.aarch64.rpm SHA-256: 6c8e5c00d79d11ceb09868c383eee806c3655413489b018bc0b64571b9dab8f8
buildah-debuginfo-1.37.6-1.el9_5.aarch64.rpm SHA-256: b1480617d5028f613eaaedfac34e8efecb37d0591b33caf880a7226765e8c11a
buildah-debugsource-1.37.6-1.el9_5.aarch64.rpm SHA-256: 7134c2aa70bb73d28190413de84a2bc2468ef56bfd9cb687c4b8e74a491a31ce
buildah-tests-1.37.6-1.el9_5.aarch64.rpm SHA-256: b5099a4e92fc7f05fdf4c57e8a620ef69a8cc90338aae1e04586b9a3b0d7b02c
buildah-tests-debuginfo-1.37.6-1.el9_5.aarch64.rpm SHA-256: ded78cdfbcbda96fae0849e4a28437b116b2501a5ce2a19dd104cad72a7a4c93

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.6

SRPM
buildah-1.37.6-1.el9_5.src.rpm SHA-256: 173a223df8a68fdc1f70b3cd8f14bf0e14d66176792877f635296111fe0df75e
ppc64le
buildah-1.37.6-1.el9_5.ppc64le.rpm SHA-256: ba2ca5a99c9401562110052ad1d06a1853df614763695c853587a723e4133982
buildah-debuginfo-1.37.6-1.el9_5.ppc64le.rpm SHA-256: 9d2ea290d8c40547be77a8f13249b8a53caff7d254771d17affcbf167941c89f
buildah-debugsource-1.37.6-1.el9_5.ppc64le.rpm SHA-256: ee4c2bcf4a5b0c5f3e083303fba01e4b2749b3f720ff7ac634b8d5734ce0941c
buildah-tests-1.37.6-1.el9_5.ppc64le.rpm SHA-256: eda5f19b1b4d32fd3a5abd2cdbaf9440e547d6e89dc373c8d82bb066914e740b
buildah-tests-debuginfo-1.37.6-1.el9_5.ppc64le.rpm SHA-256: 7848ef0eb7835e18d48a49c90dae7adf6df8ebf314126e2d80cfea02e815e7e6

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.6

SRPM
buildah-1.37.6-1.el9_5.src.rpm SHA-256: 173a223df8a68fdc1f70b3cd8f14bf0e14d66176792877f635296111fe0df75e
x86_64
buildah-1.37.6-1.el9_5.x86_64.rpm SHA-256: 48118ef2ed4f4c1d44223f2364d651e8fa46a4407f9879f4e1559eac2ab8ffaf
buildah-debuginfo-1.37.6-1.el9_5.x86_64.rpm SHA-256: 9a8810c2be5088468fd1dcd65010976d1218330dee025d31d788bda06ac3425b
buildah-debugsource-1.37.6-1.el9_5.x86_64.rpm SHA-256: 14b56d0810ccd05138c5a24475d8eec358865a7164dc48a422f43087df69d26e
buildah-tests-1.37.6-1.el9_5.x86_64.rpm SHA-256: e1ebc89443428f7a85a793d0cb793da1cab7aacf66b9abf833d9f4d1fb8d670b
buildah-tests-debuginfo-1.37.6-1.el9_5.x86_64.rpm SHA-256: 2e716d5c7e6af7fff071be5be17da9df2cfb505ed1cde6ba169b1c9ec271ac4e

Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.6

SRPM
buildah-1.37.6-1.el9_5.src.rpm SHA-256: 173a223df8a68fdc1f70b3cd8f14bf0e14d66176792877f635296111fe0df75e
aarch64
buildah-1.37.6-1.el9_5.aarch64.rpm SHA-256: 6c8e5c00d79d11ceb09868c383eee806c3655413489b018bc0b64571b9dab8f8
buildah-debuginfo-1.37.6-1.el9_5.aarch64.rpm SHA-256: b1480617d5028f613eaaedfac34e8efecb37d0591b33caf880a7226765e8c11a
buildah-debugsource-1.37.6-1.el9_5.aarch64.rpm SHA-256: 7134c2aa70bb73d28190413de84a2bc2468ef56bfd9cb687c4b8e74a491a31ce
buildah-tests-1.37.6-1.el9_5.aarch64.rpm SHA-256: b5099a4e92fc7f05fdf4c57e8a620ef69a8cc90338aae1e04586b9a3b0d7b02c
buildah-tests-debuginfo-1.37.6-1.el9_5.aarch64.rpm SHA-256: ded78cdfbcbda96fae0849e4a28437b116b2501a5ce2a19dd104cad72a7a4c93

Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.6

SRPM
buildah-1.37.6-1.el9_5.src.rpm SHA-256: 173a223df8a68fdc1f70b3cd8f14bf0e14d66176792877f635296111fe0df75e
s390x
buildah-1.37.6-1.el9_5.s390x.rpm SHA-256: b1e61fc1ab06c1be20ba7cad809986e3931890cc86e2fb2aae7e22ec0f35d62a
buildah-debuginfo-1.37.6-1.el9_5.s390x.rpm SHA-256: ea28b4bccc7628d0e0882fa75c35d47bb8aba4179162701faacce1644ed8371c
buildah-debugsource-1.37.6-1.el9_5.s390x.rpm SHA-256: 69206debe10a76eaf1f2bd04150784940021bf19d026e08e9dd7f7a19f80ab14
buildah-tests-1.37.6-1.el9_5.s390x.rpm SHA-256: 8a39d6785390ffbd25aa891498d671757884e0712915f894434e53eabde8bbd7
buildah-tests-debuginfo-1.37.6-1.el9_5.s390x.rpm SHA-256: 0fa61f62fac85d274aa6e642a95d3484c741d9bb1a224a0596827cf59fc55209

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility