Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-3056

21
FAUCET Score

CVE-2024-3056 is a denial-of-service vulnerability in Podman, affecting fedoraproject, podman_project, and redhat. An attacker can craft a malicious container that, when sharing IPC with another container, repeatedly exhausts system memory by creating unreleased IPC resources upon restart, leading to an out-of-memory condition. This high-severity flaw (CVSS 7.7) has a network attack vector with high attack complexity, requiring user interaction (restarting the malicious container) to achieve a high impact on system availability. There is no known active exploitation, public exploit code, or KEV listing, but it has garnered some community discussion and media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
<= 5.2.0CPE matchmatch criteria
cpe:2.3:a:podman_project:podman:*:*:*:*:*:*:*:*
4.0CPE matchmatch criteria
cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*
8.0CPE matchmatch criteria
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
9.0CPE matchmatch criteria
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
40CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.7HIGH

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.3
Impact Score
5.8
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.55%
Probability of exploitation in next 30 days
EPSS Percentile
42.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0054 is in the 54th percentile among its peer group of 102 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (6)

redhatvendor investigatingvia nvd_reference
View patch
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: kernel
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-rt
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (2)

goGHSA-rpcc-p8xm-rc6phigh

Podman vulnerable to memory-based denial of service

Aug 2, 2024
redhatCVE-2024-3056Moderate

podman: kernel: containers in shared IPC namespace are vulnerable to denial of service attack

Jul 25, 2024

References

security.netapp.com / advisory/ntap-20241227-0002
access.redhat.com / security/cve/CVE-2024-3056
Third Party AdvisoryVendor Advisory
bugzilla.redhat.com / show_bug.cgi
Issue Tracking