CVE-2025-9566

🟡 Monitoruj

Podman umożliwia atakującemu nadpisanie plików na hoście poprzez wykorzystanie symbolicznych linków w wolumenach Secret lub ConfigMap.

CVSS
8.1
EPSS
1.1%
Exploit
none
Vendor
Opis źródłowy (NVD)

There's a vulnerability in podman where an attacker may use the kube play command to overwrite host files when the kube file container a Secrete or a ConfigMap volume mount and such volume contains a symbolic link to a host file path. In a successful attack, the attacker can only control the target file to be overwritten but not the content to be written into the file. Binary-Affected: podman Upstream-version-introduced: v4.0.0 Upstream-version-fixed: v5.6.1

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS8.1
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)1.1%
Opublikowano (NVD)2025-09-05 20:15:36 UTC
Ostatnia modyfikacja (NVD)2026-10-08 21:17:50 UTC
Referencje