ThreatCluster

Multiple CVEs Affecting Podman and Buildah Identified

First seen 21 Feb 2026, 04:19 UTC Api.Msrc.Microsoft 73% similarity 41

Article Content

Browse articles
ThreatCluster

Two vulnerabilities affecting Podman and Buildah have been reported. CVE-2024-9407 involves improper input validation in the bind-propagation option of Dockerfile run, while CVE-2024-11218 allows for container breakout through a race condition when building a malicious containerfile. Both vulnerabilities could impact users of these container management tools.

ThreatCluster AI

Timeline

2024-10-01
CVE-2024-9407 published
2025-01-22
CVE-2024-11218 published
2026-02-18
Article on CVE-2024-11218 published
2026-02-21
Article on CVE-2024-9407 published

Community

Browse all →