CVE-2025-9566

Aliases:GHSA-wp3j-xq48-xpjwGO-2025-3935DEBIAN-CVE-2025-9566RHBA-2025:15692RHBA-2025:15712RHBA-2025:16158RHBA-2025:16163RHEA-2025:4782RHSA-2025:15900RHSA-2025:15901RHSA-2025:16480RHSA-2025:16481RHSA-2025:16482RHSA-2025:16488RHSA-2025:16515RHSA-2026:18289RHSA-2026:18722CGA-jp98-3r2v-83r9CGA-p88r-wxfw-mj7gCGA-q544-8vf8-5pr2CGA-q989-qqq3-pjq4
Deferred
Published: 05 Sept 2025, 19:54
Last modified:10 Sept 2026, 09:22

Vulnerability Summary

Overall Risk (default)
medium
33/100
CVSS Score
8.1 HIGH
v3.1 (cve.org)
EPSS Score
1.08% LOW
1% probability +0.97%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

05 Sept 2025, 19:54
Published
Vulnerability first disclosed
10 Sept 2026, 09:22
Last Modified
Vulnerability information updated

Description

There's a vulnerability in podman where an attacker may use the kube play command to overwrite host files when the kube file container a Secrete or a ConfigMap volume mount and such volume contains a symbolic link to a host file path. In a successful attack, the attacker can only control the target file to be overwritten but not the content to be written into the file. Binary-Affected: podman Upstream-version-introduced: v4.0.0 Upstream-version-fixed: v5.6.1

CVSS Metrics

  • v3.1HIGHScore: 8.1CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

EPSS Trends

Current EPSS score: 1.08% Percentile: 64%

Techniques & Countermeasures

  • CWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

    The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Affected Systems

  • chainguardprometheus-podman-exporter

    < 1.18.0-r2

  • chainguardprometheus-podman-exporter-fips

    < 1.18.0-r2

  • debianlibpod

    all | all

  • debianpodman

    all | < 5.6.1+ds1-2

  • github.com/containerspodman

    all

  • github.com/containers/podmanv2

    all

  • github.com/containers/podmanv3

    all

  • github.com/containers/podmanv4

    all | ≤ 4.9.5

  • github.com/containers/podmanv5

    < 5.6.1

  • redhataardvark-dns

    < 2:1.0.1-40.module+el8.6.0+22769+fa0fe772 | < 2:1.5.0-2.module+el8.8.0+22334+bb93e398

  • redhatbpftool

    < 0:7.3.0-427.87.1.el9_4 | < 0:7.0.0-284.138.1.el9_2

  • redhatbpftool-debuginfo

    < 0:7.3.0-427.87.1.el9_4 | < 0:7.0.0-284.138.1.el9_2

  • redhatbuildah

    < 1:1.26.9-2.module+el8.6.0+23285+f8f75f94.1 | < 1:1.29.5-1.module+el8.8.0+23219+eb2ac228.1

  • redhatbuildah-debuginfo

    < 1:1.26.9-2.module+el8.6.0+23285+f8f75f94.1 | < 1:1.29.5-1.module+el8.8.0+23219+eb2ac228.1

  • redhatbuildah-debugsource

    < 1:1.26.9-2.module+el8.6.0+23285+f8f75f94.1 | < 1:1.29.5-1.module+el8.8.0+23219+eb2ac228.1

  • redhatbuildah-tests

    < 1:1.26.9-2.module+el8.6.0+23285+f8f75f94.1 | < 1:1.29.5-1.module+el8.8.0+23219+eb2ac228.1

  • redhatbuildah-tests-debuginfo

    < 1:1.26.9-2.module+el8.6.0+23285+f8f75f94.1 | < 1:1.29.5-1.module+el8.8.0+23219+eb2ac228.1

  • redhatcockpit-podman

    < 0:49.1-1.module+el8.6.0+22769+fa0fe772 | < 0:63.1-1.module+el8.8.0+22334+bb93e398

  • redhatconmon

    < 2:2.1.4-1.module+el8.6.0+22769+fa0fe772 | < 3:2.1.6-1.module+el8.8.0+22334+bb93e398

  • redhatconmon-debuginfo

    < 2:2.1.4-1.module+el8.6.0+22769+fa0fe772 | < 3:2.1.6-1.module+el8.8.0+22334+bb93e398

  • redhatconmon-debugsource

    < 2:2.1.4-1.module+el8.6.0+22769+fa0fe772 | < 3:2.1.6-1.module+el8.8.0+22334+bb93e398

  • redhatcontainer-selinux

    < 4:2.237.0-1.rhaos4.19.el9 | < 4:2.237.0-1.rhaos4.18.el9 | < 2:2.189.0-1.module+el8.6.0+22769+fa0fe772 | < 2:2.229.0-1.module+el8.8.0+22334+bb93e398

  • redhatcontainernetworking-plugins

    < 1:1.1.1-5.module+el8.6.0+23285+f8f75f94.1 | < 1:1.2.0-3.module+el8.8.0+23219+eb2ac228

  • redhatcontainernetworking-plugins-debuginfo

    < 1:1.1.1-5.module+el8.6.0+23285+f8f75f94.1 | < 1:1.2.0-3.module+el8.8.0+23219+eb2ac228

  • redhatcontainernetworking-plugins-debugsource

    < 1:1.1.1-5.module+el8.6.0+23285+f8f75f94.1 | < 1:1.2.0-3.module+el8.8.0+23219+eb2ac228

  • redhatcontainers-common

    < 2:1-40.module+el8.6.0+22769+fa0fe772 | < 2:1-67.module+el8.8.0+22334+bb93e398

  • redhatcri-o

    < 0:1.32.8-3.rhaos4.19.git60d4e21.el9 | < 0:1.31.12-3.rhaos4.18.gitdc59c78.el8 | < 0:1.31.12-3.rhaos4.18.gitdc59c78.el9

  • redhatcri-o-debuginfo

    < 0:1.32.8-3.rhaos4.19.git60d4e21.el9 | < 0:1.31.12-3.rhaos4.18.gitdc59c78.el8 | < 0:1.31.12-3.rhaos4.18.gitdc59c78.el9

  • redhatcri-o-debugsource

    < 0:1.32.8-3.rhaos4.19.git60d4e21.el9 | < 0:1.31.12-3.rhaos4.18.gitdc59c78.el8 | < 0:1.31.12-3.rhaos4.18.gitdc59c78.el9

  • redhatcrit

    < 0:3.15-3.module+el8.6.0+22769+fa0fe772 | < 0:3.15-4.module+el8.8.0+22334+bb93e398

  • redhatcriu

    < 0:3.15-3.module+el8.6.0+22769+fa0fe772 | < 0:3.15-4.module+el8.8.0+22334+bb93e398

  • redhatcriu-debuginfo

    < 0:3.15-3.module+el8.6.0+22769+fa0fe772 | < 0:3.15-4.module+el8.8.0+22334+bb93e398

  • redhatcriu-debugsource

    < 0:3.15-3.module+el8.6.0+22769+fa0fe772 | < 0:3.15-4.module+el8.8.0+22334+bb93e398

  • redhatcriu-devel

    < 0:3.15-3.module+el8.6.0+22769+fa0fe772 | < 0:3.15-4.module+el8.8.0+22334+bb93e398

  • redhatcriu-libs

    < 0:3.15-3.module+el8.6.0+22769+fa0fe772 | < 0:3.15-4.module+el8.8.0+22334+bb93e398

  • redhatcriu-libs-debuginfo

    < 0:3.15-3.module+el8.6.0+22769+fa0fe772 | < 0:3.15-4.module+el8.8.0+22334+bb93e398

  • redhatcrun

    < 0:1.5-1.module+el8.6.0+22769+fa0fe772 | < 0:1.8.4-2.module+el8.8.0+22334+bb93e398

  • redhatcrun-debuginfo

    < 0:1.5-1.module+el8.6.0+22769+fa0fe772 | < 0:1.8.4-2.module+el8.8.0+22334+bb93e398

  • redhatcrun-debugsource

    < 0:1.5-1.module+el8.6.0+22769+fa0fe772 | < 0:1.8.4-2.module+el8.8.0+22334+bb93e398

  • redhatfuse-overlayfs

    < 0:1.9-1.module+el8.6.0+22769+fa0fe772 | < 0:1.11-1.module+el8.8.0+22334+bb93e398

  • redhatfuse-overlayfs-debuginfo

    < 0:1.9-1.module+el8.6.0+22769+fa0fe772 | < 0:1.11-1.module+el8.8.0+22334+bb93e398

  • redhatfuse-overlayfs-debugsource

    < 0:1.9-1.module+el8.6.0+22769+fa0fe772 | < 0:1.11-1.module+el8.8.0+22334+bb93e398

  • redhatkernel

    < 0:5.14.0-427.87.1.el9_4 | < 0:5.14.0-284.138.1.el9_2

  • redhatkernel-64k

    < 0:5.14.0-427.87.1.el9_4 | < 0:5.14.0-284.138.1.el9_2

  • redhatkernel-64k-core

    < 0:5.14.0-427.87.1.el9_4 | < 0:5.14.0-284.138.1.el9_2

  • redhatkernel-64k-debug

    < 0:5.14.0-427.87.1.el9_4 | < 0:5.14.0-284.138.1.el9_2

  • redhatkernel-64k-debug-core

    < 0:5.14.0-427.87.1.el9_4 | < 0:5.14.0-284.138.1.el9_2

  • redhatkernel-64k-debug-debuginfo

    < 0:5.14.0-427.87.1.el9_4 | < 0:5.14.0-284.138.1.el9_2

  • redhatkernel-64k-debug-devel

    < 0:5.14.0-427.87.1.el9_4 | < 0:5.14.0-284.138.1.el9_2

  • redhatkernel-64k-debug-devel-matched

    < 0:5.14.0-427.87.1.el9_4 | < 0:5.14.0-284.138.1.el9_2

Showing first 50 affected entries in server-rendered view.

References (63)