CVE-2025-9566

Publication date 5 September 2025

Last updated 15 September 2025


Ubuntu priority

Cvss 3 Severity Score

8.1 · High

Score breakdown

Description

There's a vulnerability in podman where an attacker may use the kube play command to overwrite host files when the kube file container a Secrete or a ConfigMap volume mount and such volume contains a symbolic link to a host file path. In a successful attack, the attacker can only control the target file to be overwritten but not the content to be written into the file. Binary-Affected: podman Upstream-version-introduced: v4.0.0 Upstream-version-fixed: v5.6.1

Status

Package Ubuntu Release Status
podman 26.04 LTS resolute
Vulnerable
25.10 questing Ignored end of life, was needed
25.04 plucky Ignored end of life, was needed
24.04 LTS noble Not in release
22.04 LTS jammy Not in release
libpod 26.04 LTS resolute Not in release
25.10 questing Not in release
25.04 plucky Not in release
24.04 LTS noble
Vulnerable
22.04 LTS jammy
Not affected

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
podman

Severity score breakdown

CVSS version: CVSS v3.0

Base score 8.1 · High

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H


Access our resources on patching vulnerabilities