CVE-2025-9566
Deferred
Deferred - Pending Action
BaseFortify
Publication date: 2025-09-05
Last updated on: 2026-05-19
Assigner: Red Hat, Inc.
Description
Description
There's a vulnerability in podman where an attacker may use the kube play command to overwrite host files when the kube file container a Secrete or a ConfigMap volume mount and such volume contains a symbolic link to a host file path. In a successful attack, the attacker can only control the target file to be overwritten but not the content to be written into the file.
Binary-Affected: podman
Upstream-version-introduced: v4.0.0
Upstream-version-fixed: v5.6.1
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| redhat | openshift_container_platform | 4.4 |
| redhat | openshift_container_platform | 4.5 |
| redhat | openshift_container_platform | 4.14 |
| redhat | openshift_container_platform | 4.8 |
| redhat | openshift_container_platform | 4.16 |
| redhat | openshift_container_platform | 4.3 |
| redhat | openshift_container_platform | 4.19.17 |
| redhat | openshift_container_platform | 4.10 |
| redhat | openshift_container_platform | 4.2 |
| redhat | openshift_container_platform | 4.1 |
| redhat | openshift_container_platform | 4.13.61 |
| redhat | openshift_container_platform | 4.9 |
| redhat | podman | * |
| redhat | openshift_container_platform | 4.18.27 |
| redhat | openshift_container_platform | 4.17.42 |
| redhat | openshift_container_platform | 4.7 |
| redhat | openshift_container_platform | 4.15 |
| redhat | openshift_container_platform | 4.11 |
| redhat | openshift_container_platform | 4.12 |
| redhat | openshift_container_platform | 4.6 |
| redhat | openshift_container_platform | 4.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-22 | The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory. |