CVE-2024-3056 is a denial-of-service vulnerability in Podman, affecting fedoraproject, podman_project, and redhat. An attacker can craft a malicious container that, when sharing IPC with another container, repeatedly exhausts system memory by creating unreleased IPC resources upon restart, leading to an out-of-memory condition. This high-severity flaw (CVSS 7.7) has a network attack vector with high attack complexity, requiring user interaction (restarting the malicious container) to achieve a high impact on system availability. There is no known active exploitation, public exploit code, or KEV listing, but it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 5.2.0CPE matchmatch criteria | cpe:2.3:a:podman_project:podman:*:*:*:*:*:*:*:* | ||
4.0CPE matchmatch criteria | cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:* | ||
40CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.