Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:1188 - Security Advisory
Issued:
2025-02-10
Updated:
2025-02-10

RHSA-2025:1188 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: buildah security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for buildah is now available for Red Hat Enterprise Linux 9.4 Extended Update Support.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The buildah package provides a tool for facilitating building OCI container images. Among other things, buildah enables you to: Create a working container, either from scratch or using an image as a starting point; Create an image, either from a working container or using the instructions in a Dockerfile; Build both Docker and OCI images.

Security Fix(es):

  • podman: buildah: Container breakout by using --jobs=2 and a race condition when building a malicious Containerfile (CVE-2024-11218)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.4 x86_64
  • Red Hat Enterprise Linux Server - AUS 9.4 x86_64
  • Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.4 s390x
  • Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.4 ppc64le
  • Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.4 aarch64
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.4 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.4 x86_64
  • Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.4 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.4 s390x

Fixes

  • BZ - 2326231 - CVE-2024-11218 podman: buildah: Container breakout by using --jobs=2 and a race condition when building a malicious Containerfile

CVEs

  • CVE-2024-11218

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.4

SRPM
buildah-1.33.12-2.el9_4.src.rpm SHA-256: 195718b791595e9f1c417977458c4bcf64cd3ca037b676549512d45e8e9f6173
x86_64
buildah-1.33.12-2.el9_4.x86_64.rpm SHA-256: e77fbbfd7ca505f375233f902f422a8ac47a26d1aeb477573315697f0c540abf
buildah-debuginfo-1.33.12-2.el9_4.x86_64.rpm SHA-256: a186d7710aed30c629cdb8949c4ab47179aa4ec0941c385dfa30a397796a1ef7
buildah-debugsource-1.33.12-2.el9_4.x86_64.rpm SHA-256: f3462787ce0c5c177796a42c149e041de0b4647e377e7e464f8881b80db4c57c
buildah-tests-1.33.12-2.el9_4.x86_64.rpm SHA-256: cccbed9a31293ebb6b73f28cc61c84e40e031fe662506aebb7f7fa0367587fb9
buildah-tests-debuginfo-1.33.12-2.el9_4.x86_64.rpm SHA-256: b7629185a9345e95790fd81799b16a2d5fa6f9b8c25f2ef5269a47b91767486f

Red Hat Enterprise Linux Server - AUS 9.4

SRPM
buildah-1.33.12-2.el9_4.src.rpm SHA-256: 195718b791595e9f1c417977458c4bcf64cd3ca037b676549512d45e8e9f6173
x86_64
buildah-1.33.12-2.el9_4.x86_64.rpm SHA-256: e77fbbfd7ca505f375233f902f422a8ac47a26d1aeb477573315697f0c540abf
buildah-debuginfo-1.33.12-2.el9_4.x86_64.rpm SHA-256: a186d7710aed30c629cdb8949c4ab47179aa4ec0941c385dfa30a397796a1ef7
buildah-debugsource-1.33.12-2.el9_4.x86_64.rpm SHA-256: f3462787ce0c5c177796a42c149e041de0b4647e377e7e464f8881b80db4c57c
buildah-tests-1.33.12-2.el9_4.x86_64.rpm SHA-256: cccbed9a31293ebb6b73f28cc61c84e40e031fe662506aebb7f7fa0367587fb9
buildah-tests-debuginfo-1.33.12-2.el9_4.x86_64.rpm SHA-256: b7629185a9345e95790fd81799b16a2d5fa6f9b8c25f2ef5269a47b91767486f

Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.4

SRPM
buildah-1.33.12-2.el9_4.src.rpm SHA-256: 195718b791595e9f1c417977458c4bcf64cd3ca037b676549512d45e8e9f6173
s390x
buildah-1.33.12-2.el9_4.s390x.rpm SHA-256: f9324f930539cc8c2d4477377bbc5de6a309195e9add8ed8c728198d14c1f857
buildah-debuginfo-1.33.12-2.el9_4.s390x.rpm SHA-256: 4890b542dda65f64c0b34c33cc598b61554f8bedb5ae914dc5b7be3fb765e478
buildah-debugsource-1.33.12-2.el9_4.s390x.rpm SHA-256: f1665512395c05d4366b520d864ab4d8efb159200e9e653f7f97fc9bea1368de
buildah-tests-1.33.12-2.el9_4.s390x.rpm SHA-256: 2abf5f716b2b370a05e76c2426f517e025af9edf10233550eca2c359ad2f69f5
buildah-tests-debuginfo-1.33.12-2.el9_4.s390x.rpm SHA-256: b63f4078a9c383a3ba04f3a1c7c9ccd4d21fa614f918b71c3cb8c55c36cddee9

Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.4

SRPM
buildah-1.33.12-2.el9_4.src.rpm SHA-256: 195718b791595e9f1c417977458c4bcf64cd3ca037b676549512d45e8e9f6173
ppc64le
buildah-1.33.12-2.el9_4.ppc64le.rpm SHA-256: c60e2d7ee0b4bf48595809834c4e7e7f7e02b38c09d459d9eef1ee979f726f59
buildah-debuginfo-1.33.12-2.el9_4.ppc64le.rpm SHA-256: 641f05c5761d97b528b520d481f039f540f4dcee70f80740a3e9c3f938d63aaf
buildah-debugsource-1.33.12-2.el9_4.ppc64le.rpm SHA-256: 0bd8b898f217d9213fc33dd95ff68f75abb2b7b93081258745fd9c0745bd03b5
buildah-tests-1.33.12-2.el9_4.ppc64le.rpm SHA-256: 3ce55276abe473931ee9dc92757b99863f06a7e7da061c5d44421a4bc1f3483a
buildah-tests-debuginfo-1.33.12-2.el9_4.ppc64le.rpm SHA-256: c36c9574ff24b6e02ba7dfb880988f2e5781ce41873003d0478a1dc69563ac4d

Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.4

SRPM
buildah-1.33.12-2.el9_4.src.rpm SHA-256: 195718b791595e9f1c417977458c4bcf64cd3ca037b676549512d45e8e9f6173
aarch64
buildah-1.33.12-2.el9_4.aarch64.rpm SHA-256: 2f52b43a0f194eb2707fc0e1693f0e6cd898f7965cc8f579c36e127987519f10
buildah-debuginfo-1.33.12-2.el9_4.aarch64.rpm SHA-256: 9c1d376362aec807b45d447e0937aadd210cf6b94de7b4bc1376b7336dde25ca
buildah-debugsource-1.33.12-2.el9_4.aarch64.rpm SHA-256: b634bd2dc4414070f21bdb49970084015a87b1607a913371d1a0fc2cd2189e36
buildah-tests-1.33.12-2.el9_4.aarch64.rpm SHA-256: a7d675eded96e903af96f82108edaa955fc46f8f6075f587126e041bf4defa9b
buildah-tests-debuginfo-1.33.12-2.el9_4.aarch64.rpm SHA-256: 1922bd098611fc4f4bae72c87996147a95dd122cedcaa300178a6853c8916eae

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.4

SRPM
buildah-1.33.12-2.el9_4.src.rpm SHA-256: 195718b791595e9f1c417977458c4bcf64cd3ca037b676549512d45e8e9f6173
ppc64le
buildah-1.33.12-2.el9_4.ppc64le.rpm SHA-256: c60e2d7ee0b4bf48595809834c4e7e7f7e02b38c09d459d9eef1ee979f726f59
buildah-debuginfo-1.33.12-2.el9_4.ppc64le.rpm SHA-256: 641f05c5761d97b528b520d481f039f540f4dcee70f80740a3e9c3f938d63aaf
buildah-debugsource-1.33.12-2.el9_4.ppc64le.rpm SHA-256: 0bd8b898f217d9213fc33dd95ff68f75abb2b7b93081258745fd9c0745bd03b5
buildah-tests-1.33.12-2.el9_4.ppc64le.rpm SHA-256: 3ce55276abe473931ee9dc92757b99863f06a7e7da061c5d44421a4bc1f3483a
buildah-tests-debuginfo-1.33.12-2.el9_4.ppc64le.rpm SHA-256: c36c9574ff24b6e02ba7dfb880988f2e5781ce41873003d0478a1dc69563ac4d

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.4

SRPM
buildah-1.33.12-2.el9_4.src.rpm SHA-256: 195718b791595e9f1c417977458c4bcf64cd3ca037b676549512d45e8e9f6173
x86_64
buildah-1.33.12-2.el9_4.x86_64.rpm SHA-256: e77fbbfd7ca505f375233f902f422a8ac47a26d1aeb477573315697f0c540abf
buildah-debuginfo-1.33.12-2.el9_4.x86_64.rpm SHA-256: a186d7710aed30c629cdb8949c4ab47179aa4ec0941c385dfa30a397796a1ef7
buildah-debugsource-1.33.12-2.el9_4.x86_64.rpm SHA-256: f3462787ce0c5c177796a42c149e041de0b4647e377e7e464f8881b80db4c57c
buildah-tests-1.33.12-2.el9_4.x86_64.rpm SHA-256: cccbed9a31293ebb6b73f28cc61c84e40e031fe662506aebb7f7fa0367587fb9
buildah-tests-debuginfo-1.33.12-2.el9_4.x86_64.rpm SHA-256: b7629185a9345e95790fd81799b16a2d5fa6f9b8c25f2ef5269a47b91767486f

Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.4

SRPM
buildah-1.33.12-2.el9_4.src.rpm SHA-256: 195718b791595e9f1c417977458c4bcf64cd3ca037b676549512d45e8e9f6173
aarch64
buildah-1.33.12-2.el9_4.aarch64.rpm SHA-256: 2f52b43a0f194eb2707fc0e1693f0e6cd898f7965cc8f579c36e127987519f10
buildah-debuginfo-1.33.12-2.el9_4.aarch64.rpm SHA-256: 9c1d376362aec807b45d447e0937aadd210cf6b94de7b4bc1376b7336dde25ca
buildah-debugsource-1.33.12-2.el9_4.aarch64.rpm SHA-256: b634bd2dc4414070f21bdb49970084015a87b1607a913371d1a0fc2cd2189e36
buildah-tests-1.33.12-2.el9_4.aarch64.rpm SHA-256: a7d675eded96e903af96f82108edaa955fc46f8f6075f587126e041bf4defa9b
buildah-tests-debuginfo-1.33.12-2.el9_4.aarch64.rpm SHA-256: 1922bd098611fc4f4bae72c87996147a95dd122cedcaa300178a6853c8916eae

Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.4

SRPM
buildah-1.33.12-2.el9_4.src.rpm SHA-256: 195718b791595e9f1c417977458c4bcf64cd3ca037b676549512d45e8e9f6173
s390x
buildah-1.33.12-2.el9_4.s390x.rpm SHA-256: f9324f930539cc8c2d4477377bbc5de6a309195e9add8ed8c728198d14c1f857
buildah-debuginfo-1.33.12-2.el9_4.s390x.rpm SHA-256: 4890b542dda65f64c0b34c33cc598b61554f8bedb5ae914dc5b7be3fb765e478
buildah-debugsource-1.33.12-2.el9_4.s390x.rpm SHA-256: f1665512395c05d4366b520d864ab4d8efb159200e9e653f7f97fc9bea1368de
buildah-tests-1.33.12-2.el9_4.s390x.rpm SHA-256: 2abf5f716b2b370a05e76c2426f517e025af9edf10233550eca2c359ad2f69f5
buildah-tests-debuginfo-1.33.12-2.el9_4.s390x.rpm SHA-256: b63f4078a9c383a3ba04f3a1c7c9ccd4d21fa614f918b71c3cb8c55c36cddee9

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility