PT-2026-50742 · Podman+1 · Podman+1
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Podman versions prior to 5.7.1
Description
Running a malicious container image where the
WORKDIR path contains a symlink can allow an attacker to create a directory or modify ownership on the host filesystem. Modifying ownership is less likely as it requires a race condition triggered by an untrusted process mutating the host filesystem tree during the dereferencing of the WORKDIR path.Recommendations
Update Podman to version 5.7.1 or later.
Exploit
Fix
DoS
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Podman
Red Os