CVE-2025-9566
Vulnerability Summary
Timeline
Description
There's a vulnerability in podman where an attacker may use the kube play command to overwrite host files when the kube file container a Secrete or a ConfigMap volume mount and such volume contains a symbolic link to a host file path. In a successful attack, the attacker can only control the target file to be overwritten but not the content to be written into the file. Binary-Affected: podman Upstream-version-introduced: v4.0.0 Upstream-version-fixed: v5.6.1
CVSS Metrics
- v3.1•HIGH•Score: 8.1CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
EPSS Trends
Current EPSS score: 1.08%• Percentile: 64%
Techniques & Countermeasures
- CWE-22•Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Affected Systems
- chainguard•prometheus-podman-exporter
< 1.18.0-r2
- chainguard•prometheus-podman-exporter-fips
< 1.18.0-r2
- debian•libpod
all | all
- debian•podman
all | < 5.6.1+ds1-2
- github.com/containers•podman
all
- github.com/containers/podman•v2
all
- github.com/containers/podman•v3
all
- github.com/containers/podman•v4
all | ≤ 4.9.5
- github.com/containers/podman•v5
< 5.6.1
- redhat•aardvark-dns
< 2:1.0.1-40.module+el8.6.0+22769+fa0fe772 | < 2:1.5.0-2.module+el8.8.0+22334+bb93e398
- redhat•bpftool
< 0:7.3.0-427.87.1.el9_4 | < 0:7.0.0-284.138.1.el9_2
- redhat•bpftool-debuginfo
< 0:7.3.0-427.87.1.el9_4 | < 0:7.0.0-284.138.1.el9_2
- redhat•buildah
< 1:1.26.9-2.module+el8.6.0+23285+f8f75f94.1 | < 1:1.29.5-1.module+el8.8.0+23219+eb2ac228.1
- redhat•buildah-debuginfo
< 1:1.26.9-2.module+el8.6.0+23285+f8f75f94.1 | < 1:1.29.5-1.module+el8.8.0+23219+eb2ac228.1
- redhat•buildah-debugsource
< 1:1.26.9-2.module+el8.6.0+23285+f8f75f94.1 | < 1:1.29.5-1.module+el8.8.0+23219+eb2ac228.1
- redhat•buildah-tests
< 1:1.26.9-2.module+el8.6.0+23285+f8f75f94.1 | < 1:1.29.5-1.module+el8.8.0+23219+eb2ac228.1
- redhat•buildah-tests-debuginfo
< 1:1.26.9-2.module+el8.6.0+23285+f8f75f94.1 | < 1:1.29.5-1.module+el8.8.0+23219+eb2ac228.1
- redhat•cockpit-podman
< 0:49.1-1.module+el8.6.0+22769+fa0fe772 | < 0:63.1-1.module+el8.8.0+22334+bb93e398
- redhat•conmon
< 2:2.1.4-1.module+el8.6.0+22769+fa0fe772 | < 3:2.1.6-1.module+el8.8.0+22334+bb93e398
- redhat•conmon-debuginfo
< 2:2.1.4-1.module+el8.6.0+22769+fa0fe772 | < 3:2.1.6-1.module+el8.8.0+22334+bb93e398
- redhat•conmon-debugsource
< 2:2.1.4-1.module+el8.6.0+22769+fa0fe772 | < 3:2.1.6-1.module+el8.8.0+22334+bb93e398
- redhat•container-selinux
< 4:2.237.0-1.rhaos4.19.el9 | < 4:2.237.0-1.rhaos4.18.el9 | < 2:2.189.0-1.module+el8.6.0+22769+fa0fe772 | < 2:2.229.0-1.module+el8.8.0+22334+bb93e398
- redhat•containernetworking-plugins
< 1:1.1.1-5.module+el8.6.0+23285+f8f75f94.1 | < 1:1.2.0-3.module+el8.8.0+23219+eb2ac228
- redhat•containernetworking-plugins-debuginfo
< 1:1.1.1-5.module+el8.6.0+23285+f8f75f94.1 | < 1:1.2.0-3.module+el8.8.0+23219+eb2ac228
- redhat•containernetworking-plugins-debugsource
< 1:1.1.1-5.module+el8.6.0+23285+f8f75f94.1 | < 1:1.2.0-3.module+el8.8.0+23219+eb2ac228
- redhat•containers-common
< 2:1-40.module+el8.6.0+22769+fa0fe772 | < 2:1-67.module+el8.8.0+22334+bb93e398
- redhat•cri-o
< 0:1.32.8-3.rhaos4.19.git60d4e21.el9 | < 0:1.31.12-3.rhaos4.18.gitdc59c78.el8 | < 0:1.31.12-3.rhaos4.18.gitdc59c78.el9
- redhat•cri-o-debuginfo
< 0:1.32.8-3.rhaos4.19.git60d4e21.el9 | < 0:1.31.12-3.rhaos4.18.gitdc59c78.el8 | < 0:1.31.12-3.rhaos4.18.gitdc59c78.el9
- redhat•cri-o-debugsource
< 0:1.32.8-3.rhaos4.19.git60d4e21.el9 | < 0:1.31.12-3.rhaos4.18.gitdc59c78.el8 | < 0:1.31.12-3.rhaos4.18.gitdc59c78.el9
- redhat•crit
< 0:3.15-3.module+el8.6.0+22769+fa0fe772 | < 0:3.15-4.module+el8.8.0+22334+bb93e398
- redhat•criu
< 0:3.15-3.module+el8.6.0+22769+fa0fe772 | < 0:3.15-4.module+el8.8.0+22334+bb93e398
- redhat•criu-debuginfo
< 0:3.15-3.module+el8.6.0+22769+fa0fe772 | < 0:3.15-4.module+el8.8.0+22334+bb93e398
- redhat•criu-debugsource
< 0:3.15-3.module+el8.6.0+22769+fa0fe772 | < 0:3.15-4.module+el8.8.0+22334+bb93e398
- redhat•criu-devel
< 0:3.15-3.module+el8.6.0+22769+fa0fe772 | < 0:3.15-4.module+el8.8.0+22334+bb93e398
- redhat•criu-libs
< 0:3.15-3.module+el8.6.0+22769+fa0fe772 | < 0:3.15-4.module+el8.8.0+22334+bb93e398
- redhat•criu-libs-debuginfo
< 0:3.15-3.module+el8.6.0+22769+fa0fe772 | < 0:3.15-4.module+el8.8.0+22334+bb93e398
- redhat•crun
< 0:1.5-1.module+el8.6.0+22769+fa0fe772 | < 0:1.8.4-2.module+el8.8.0+22334+bb93e398
- redhat•crun-debuginfo
< 0:1.5-1.module+el8.6.0+22769+fa0fe772 | < 0:1.8.4-2.module+el8.8.0+22334+bb93e398
- redhat•crun-debugsource
< 0:1.5-1.module+el8.6.0+22769+fa0fe772 | < 0:1.8.4-2.module+el8.8.0+22334+bb93e398
- redhat•fuse-overlayfs
< 0:1.9-1.module+el8.6.0+22769+fa0fe772 | < 0:1.11-1.module+el8.8.0+22334+bb93e398
- redhat•fuse-overlayfs-debuginfo
< 0:1.9-1.module+el8.6.0+22769+fa0fe772 | < 0:1.11-1.module+el8.8.0+22334+bb93e398
- redhat•fuse-overlayfs-debugsource
< 0:1.9-1.module+el8.6.0+22769+fa0fe772 | < 0:1.11-1.module+el8.8.0+22334+bb93e398
- redhat•kernel
< 0:5.14.0-427.87.1.el9_4 | < 0:5.14.0-284.138.1.el9_2
- redhat•kernel-64k
< 0:5.14.0-427.87.1.el9_4 | < 0:5.14.0-284.138.1.el9_2
- redhat•kernel-64k-core
< 0:5.14.0-427.87.1.el9_4 | < 0:5.14.0-284.138.1.el9_2
- redhat•kernel-64k-debug
< 0:5.14.0-427.87.1.el9_4 | < 0:5.14.0-284.138.1.el9_2
- redhat•kernel-64k-debug-core
< 0:5.14.0-427.87.1.el9_4 | < 0:5.14.0-284.138.1.el9_2
- redhat•kernel-64k-debug-debuginfo
< 0:5.14.0-427.87.1.el9_4 | < 0:5.14.0-284.138.1.el9_2
- redhat•kernel-64k-debug-devel
< 0:5.14.0-427.87.1.el9_4 | < 0:5.14.0-284.138.1.el9_2
- redhat•kernel-64k-debug-devel-matched
< 0:5.14.0-427.87.1.el9_4 | < 0:5.14.0-284.138.1.el9_2
Showing first 50 affected entries in server-rendered view.
References (63)
- https://access.redhat.com/errata/RHSA-2025:15900
- https://access.redhat.com/errata/RHSA-2025:15901
- https://access.redhat.com/errata/RHSA-2025:15904
- https://access.redhat.com/errata/RHSA-2025:16480
- https://access.redhat.com/errata/RHSA-2025:16481
- https://access.redhat.com/errata/RHSA-2025:16482
- https://access.redhat.com/errata/RHSA-2025:16488
- https://access.redhat.com/errata/RHSA-2025:16515
- https://access.redhat.com/errata/RHSA-2025:18217
- https://access.redhat.com/errata/RHSA-2025:18218
- https://access.redhat.com/errata/RHSA-2025:18240
- https://access.redhat.com/errata/RHSA-2025:19002
- https://access.redhat.com/errata/RHSA-2025:19041
- https://access.redhat.com/errata/RHSA-2025:19046
- https://access.redhat.com/errata/RHSA-2025:19094
- https://access.redhat.com/errata/RHSA-2025:19894
- https://access.redhat.com/errata/RHSA-2025:20909
- https://access.redhat.com/errata/RHSA-2025:20983
- https://access.redhat.com/security/cve/CVE-2025-9566
- https://bugzilla.redhat.com/show_bug.cgi?id=2393152
- https://github.com/containers/podman/security/advisories/GHSA-wp3j-xq48-xpjw
- https://nvd.nist.gov/vuln/detail/CVE-2025-9566
- https://github.com/containers/podman/commit/43fbde4e665fe6cee6921868f04b7ccd3de5ad89
- https://github.com/containers/podman
- https://access.redhat.com/errata/RHBA-2025:16158
- https://access.redhat.com/errata/RHSA-2025:16724
- https://access.redhat.com/errata/RHBA-2025:15692
- https://access.redhat.com/errata/RHBA-2025:15712
- https://access.redhat.com/errata/RHEA-2025:4782
- https://access.redhat.com/errata/RHSA-2025:17669
- https://access.redhat.com/errata/RHBA-2025:16163
- https://access.redhat.com/errata/RHSA-2026:8211
- https://access.redhat.com/errata/RHSA-2026:18289
- https://access.redhat.com/errata/RHSA-2026:18722
- https://security-tracker.debian.org/tracker/CVE-2025-9566
- https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhba-2025_15692.json
- https://www.cve.org/CVERecord?id=CVE-2025-9566
- https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhba-2025_15712.json
- https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhba-2025_16158.json
- https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhba-2025_16163.json
- https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhea-2025_4782.json
- https://access.redhat.com/security/updates/classification/#important
- https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_15900.json
- https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_15901.json
- https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_16480.json
- https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_16481.json
- https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_16482.json
- https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_16488.json
- https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_16515.json
- https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/10/html/10.2_release_notes/index
- https://issues.redhat.com/browse/RHEL-132823
- https://issues.redhat.com/browse/RHEL-145596
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_18289.json
- https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/9/html/9.8_release_notes/index
- https://issues.redhat.com/browse/RHEL-127541
- https://issues.redhat.com/browse/RHEL-132826
- https://issues.redhat.com/browse/RHEL-142896
- https://issues.redhat.com/browse/RHEL-15873
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_18722.json
- https://access.redhat.com/downloads/content/package-browser/
- https://catalog.redhat.com/software/containers/
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/9xxx/CVE-2025-9566.json
- https://access.redhat.com/errata/RHSA-2026:62549