PT-2025-36328 · Red Hat+7 · Podman+8
Paul Holzinger
·
Published
2025-01-01
·
Updated
2026-05-19
·
CVE-2025-9566
CVSS v2.0
8.5
High
| Vector | AV:N/AC:L/Au:S/C:N/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
podman versions 4.0.0 through 5.6.1
Description
A vulnerability exists in podman where an attacker can use the
kube play command to overwrite host files. This occurs when the kube file contains a Secret or a ConfigMap volume mount, and that volume contains a symbolic link to a host file path. In a successful attack, the attacker can control the target file to be overwritten but not the content written into the file.Recommendations
Update podman to version 5.6.1 or later.
Fix
DoS
Path traversal
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Almalinux
Centos
Debian
Red Hat
Red Os
Rocky Linux
Suse
Podman