CVE-2025-9566

HIGH

Red Hat Enterprise Linux 10 - Path Traversal via Podman Kube Play Command

Title source: llm
STIX 2.1

Description

There's a vulnerability in podman where an attacker may use the kube play command to overwrite host files when the kube file container a Secrete or a ConfigMap volume mount and such volume contains a symbolic link to a host file path. In a successful attack, the attacker can only control the target file to be overwritten but not the content to be written into the file. Binary-Affected: podman Upstream-version-introduced: v4.0.0 Upstream-version-fixed: v5.6.1

References (32)

Core 32
Core References
Vendor Advisory vendor-advisory x_refsource_redhat
RHSA-2026:8211
https://access.redhat.com/errata/RHSA-2026:8211
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHBA-2025:15692
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHBA-2025:15712
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHBA-2025:16158
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHBA-2025:16163
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHEA-2025:4782
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2025:15900
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2025:15901
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2025:15904
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2025:16480
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2025:16481
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2025:16482
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2025:16488
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2025:16515
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2025:16724
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2025:17669
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2025:18217
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2025:18218
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2025:18240
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2025:19002
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2025:19041
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2025:19046
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2025:19094
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2025:19894
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2025:20909
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2025:20983
Vendor Advisory vendor-advisory x_refsource_redhat
RHSA-2026:18289
https://access.redhat.com/errata/RHSA-2026:18289
Vendor Advisory vendor-advisory x_refsource_redhat
RHSA-2026:18722
https://access.redhat.com/errata/RHSA-2026:18722
Vendor Advisory vdb-entry x_refsource_redhat
https://access.redhat.com/security/cve/CVE-2025-9566
Issue Tracking issue-tracking x_refsource_redhat
https://bugzilla.redhat.com/show_bug.cgi?id=2393152

Scores

CVSS v3 8.1
EPSS 0.0101
EPSS Percentile 58.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (50)
containers/podman 0 - 4.9.5Go
containers/podman 0 - 5.6.1Go
Red Hat/Red Hat Enterprise Linux 10 6:5.4.0-13.el10_0
Red Hat/Red Hat Enterprise Linux 10 7:5.6.0-5.el10_1
Red Hat/Red Hat Enterprise Linux 10 7:5.8.0-2.el10
Red Hat/Red Hat Enterprise Linux 8 8100020250911075811.afee755d
Red Hat/Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support 8060020250919150821.3b538bd8
Red Hat/Red Hat Enterprise Linux 8.6 Telecommunications Update Service 8060020250919150821.3b538bd8
Red Hat/Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions 8060020250919150821.3b538bd8
Red Hat/Red Hat Enterprise Linux 8.8 Telecommunications Update Service 8080020250919060528.0f77c1b7
... and 40 more
Published Sep 05, 2025
Tracked Since Feb 18, 2026