PT-2026-50742 · Podman+1 · Podman+1

·

CVE-2026-55686

·

Published

2026-06-18

·

Updated

2026-08-20

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Podman versions prior to 5.7.1
Description Running a malicious container image where the WORKDIR path contains a symlink can allow an attacker to create a directory or modify ownership on the host filesystem. Modifying ownership is less likely as it requires a race condition triggered by an untrusted process mutating the host filesystem tree during the dereferencing of the WORKDIR path.
Recommendations Update Podman to version 5.7.1 or later.

Exploit

Fix

DoS

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-91299
CVE-2026-55686
GHSA-Q6R4-3WMG-FWCQ
GO-2026-5568
OPENSUSE-SU-2026:21483-1
RHSA-2026:29954
SUSE-SU-2026:23205-1
SUSE-SU-2026:3536-1
SUSE-SU-2026:3652-1
SUSE-SU-2026:3662-1

Affected Products

Podman
Red Os