<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T16:56:03.178801+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2025:15900</id>
    <title>ALSA-2025:15900 — Important: podman security update</title>
    <updated>2026-10-02T16:56:03.281319+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: podman, AlmaLinux:9: podman-docker, AlmaLinux:9: podman-plugins, AlmaLinux:9: podman-remote, AlmaLinux:9: podman-tests</p>
<p>The podman tool manages pods, container images, and containers. It is part of the libpod library, which is for applications that use container pods. Container pods is a concept in Kubernetes.</p>
<p>Security Fix(es):</p>
<p>* podman: Podman kube play command may overwrite host files (CVE-2025-9566)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2025:15900"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-13147</id>
    <title>bdu:2025-13147</title>
    <updated>2026-10-02T16:56:03.281440+00:00</updated>
    <content>bdu:2025-13147</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-13147"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2025-9566</id>
    <title>BELL-CVE-2025-9566</title>
    <updated>2026-10-02T16:56:03.281463+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: podman, Alpaquita:25: podman, Alpaquita:stream: podman</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2025-9566"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-377382</id>
    <title>EUVD-2026-377382</title>
    <updated>2026-10-02T16:56:03.281487+00:00</updated>
    <content>EUVD-2026-377382</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-377382"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-9566</id>
    <title>fkie_cve-2025-9566</title>
    <updated>2026-10-02T16:56:03.281510+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>There's a vulnerability in podman where an attacker may use the kube play command to overwrite host files when the kube file container a Secrete or a ConfigMap volume mount and such volume contains a symbolic link to a host file path. In a successful attack, the attacker can only control the target file to be overwritten but not the content to be written into the file.</p>
<p>Binary-Affected: podman
Upstream-version-introduced: v4.0.0
Upstream-version-fixed: v5.6.1</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-9566"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-wp3j-xq48-xpjw</id>
    <title>GHSA-wp3j-xq48-xpjw — podman kube play symlink traversal vulnerability</title>
    <updated>2026-10-02T16:56:03.281554+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/containers/podman/v5, Go: github.com/containers/podman/v4</p>
<p>### Impact</p>
<p>The podman kube play command can overwrite host files when the kube file contains a ConfigMap or Secret volume mount and the volume already contains a symlink to a host file.
This allows a malicious container to write to arbitrary files on the host BUT the attacker only controls the target path not the contents that will be written to the file. The contents are defined in the yaml file by the end user.</p>
<p>### Requirements to exploit:
podman kube play must be used with a ConfigMap or Secret volume mount AND must be run more than once on the same volume. All the attacker has to do is create the malicious symlink on the volume the first time it is started. After that all following starts would follow the symlink and write to the host location.</p>
<p>### Patches
Fixed in podman v5.6.1
https://github.com/containers/podman/commit/43fbde4e665fe6cee6921868f04b7ccd3de5ad89</p>
<p>### Workarounds</p>
<p>Don't use podman kube play with ConfigMap or Secret volume mounts.</p>
<p>### PR with test for CI</p>
<p>Adding on 9/8/2025 by @TomSweeneyRedHat , this is the PR containing the test in CI: https://github.com/containers/podman/pull/27001</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-wp3j-xq48-xpjw"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-9566</id>
    <title>msrc_CVE-2025-9566 — Podman: podman kube play command may overwrite host files</title>
    <updated>2026-10-02T16:56:03.281630+00:00</updated>
    <content>msrc_CVE-2025-9566</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-9566"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15538-1</id>
    <title>openSUSE-SU-2025:15538-1 — govulncheck-vulndb-0.0.20250908T141310-1.1 on GA media</title>
    <updated>2026-10-02T16:56:03.281660+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>govulncheck-vulndb-0.0.20250908T141310-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:15538-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhba-2025:15692</id>
    <title>RHBA-2025:15692 — Red Hat Bug Fix Advisory: OpenShift Container Platform 4.19.12 packages update</title>
    <updated>2026-10-02T16:56:03.281700+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>podman: Podman kube play command may overwrite host files</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhba-2025:15692"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:03534-1</id>
    <title>SUSE-SU-2025:03534-1 — Security update for podman</title>
    <updated>2026-10-02T16:56:03.281732+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for podman</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:03534-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-9566</id>
    <title>UBUNTU-CVE-2025-9566</title>
    <updated>2026-10-02T16:56:03.281758+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:24.04:LTS: libpod, Ubuntu:25.10: podman, Ubuntu:26.04:LTS: podman</p>
<p>There's a vulnerability in podman where an attacker may use the kube play command to overwrite host files when the kube file container a Secrete or a ConfigMap volume mount and such volume contains a symbolic link to a host file path. In a successful attack, the attacker can only control the target file to be overwritten but not the content to be written into the file. Binary-Affected: podman Upstream-version-introduced: v4.0.0 Upstream-version-fixed: v5.6.1</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-9566"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1974</id>
    <title>WID-SEC-W-2025-1974 — Podman: Schwachstelle ermöglicht Manipulation von Dateien</title>
    <updated>2026-10-02T16:56:03.281805+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Podman ausnutzen, um Dateien zu manipulieren.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1974"/>
  </entry>
</feed>
