A flaw was found in Podman. If an attacker can pass a crafted tar archive to the `podman load` command, they can create files on the host machine with the privileges of the user running Podman.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade podman | Sep 30, 2026 | Sep 15, 2026 |
| Freebsd | — | Upgrade podman | Sep 25, 2026 | Sep 24, 2026 |
| Redhat_linux | — | Upgrade buildah-debugsourceUpgrade buildah-tests-debuginfoUpgrade skopeo-testsUpgrade skopeoUpgrade buildah-debuginfoUpgrade skopeo-debuginfoUpgrade skopeo-debugsourceUpgrade buildah-testsUpgrade buildahNo solution exists | Sep 17, 2026 | Nov 7, 2025 |
| Rocky_linux | — | Upgrade buildah-tests-debuginfoUpgrade buildah-debugsourceUpgrade skopeoUpgrade skopeo-testsUpgrade skopeo-debuginfoUpgrade buildah-debuginfoUpgrade skopeo-debugsourceUpgrade buildah-testsUpgrade buildah | Sep 28, 2026 | Sep 24, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub