CVE-2025-9566

Name
CVE-2025-9566
Description
There's a vulnerability in podman where an attacker may use the kube play command to overwrite host files when the kube file container a Secrete or a ConfigMap volume mount and such volume contains a symbolic link to a host file path. In a successful attack, the attacker can only control the target file to be overwritten but not the content to be written into the file. Binary-Affected: podman Upstream-version-introduced: v4.0.0 Upstream-version-fixed: v5.6.1
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
vdb-entry https://access.redhat.com/security/cve/CVE-2025-9566
issue-tracking https://bugzilla.redhat.com/show_bug.cgi?id=2393152
secalert@redhat.com https://access.redhat.com/errata/RHSA-2025:15900
secalert@redhat.com https://access.redhat.com/errata/RHSA-2025:15901
secalert@redhat.com https://access.redhat.com/errata/RHSA-2025:15904
secalert@redhat.com https://access.redhat.com/errata/RHSA-2025:16480
secalert@redhat.com https://access.redhat.com/errata/RHSA-2025:16482
secalert@redhat.com https://access.redhat.com/errata/RHSA-2025:16481
secalert@redhat.com https://access.redhat.com/errata/RHSA-2025:16488
secalert@redhat.com https://access.redhat.com/errata/RHSA-2025:16515
secalert@redhat.com https://access.redhat.com/errata/RHSA-2025:18218
secalert@redhat.com https://access.redhat.com/errata/RHSA-2025:18217
secalert@redhat.com https://access.redhat.com/errata/RHSA-2025:19094
secalert@redhat.com https://access.redhat.com/errata/RHSA-2025:18240
secalert@redhat.com https://access.redhat.com/errata/RHSA-2025:19046
secalert@redhat.com https://access.redhat.com/errata/RHSA-2025:19041
secalert@redhat.com https://access.redhat.com/errata/RHSA-2025:19002
secalert@redhat.com https://access.redhat.com/errata/RHSA-2025:20909
secalert@redhat.com https://access.redhat.com/errata/RHSA-2025:20983
secalert@redhat.com https://access.redhat.com/errata/RHSA-2025:19894

Match rules

CPE URI Source package Min version Max version

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
podman edge-community 5.6.1-r0 Michał Polański <michal@polanski.me> fixed
podman 3.22-community 5.6.1-r0 Michał Polański <michal@polanski.me> fixed