#1710 [podman] CVE-2024-9675 podman: Buildah allows arbitrary directory mount [fedora-all] | rhbz#2317464
Closed by blockerbot. Opened by blockerbot.

Bug details: ** https://bugzilla.redhat.com/show_bug.cgi?id=2317464 **
Information from BlockerBugs App:
2317464

Current vote summary

The votes have been last counted at 2024-10-18 18:35 UTC and the last processed comment was #comment-939259

To learn how to vote, see:
https://pagure.io/fedora-qa/blocker-review
A quick example: BetaBlocker +1 (where the tracker name is one of BetaBlocker/FinalBlocker/BetaFE/FinalFE/0Day/PreviousRelease and the vote is one of +1/0/-1)


The criterion is "The release must contain no known security bugs of 'important' or higher impact according to the Red Hat severity classification scale which cannot be satisfactorily resolved by a package update (e.g. issues during installation)." https://access.redhat.com/security/cve/CVE-2024-9675 has this as Important. I think it's maybe reasonable to consider it "cannot be satisfactorily resolved by a package update" because we do ship Fedora CoreOS, which is specifically intended for deploying containers, and that won't get the fix until it's in stable. So, I think I'm gonna say:

FinalBlocker +1

AGREED AcceptedFinalBlocker

The following votes have been closed:

Metadata Update from @blockerbot:
- Issue status updated to: Closed (was: Open)

Release F41 is no longer tracked by BlockerBugs, closing this ticket.

Log in to comment on this ticket.

Metadata