CVE-2025-9566
HIGHRed Hat Enterprise Linux 10 - Path Traversal via Podman Kube Play Command
Title source: llmDescription
There's a vulnerability in podman where an attacker may use the kube play command to overwrite host files when the kube file container a Secrete or a ConfigMap volume mount and such volume contains a symbolic link to a host file path. In a successful attack, the attacker can only control the target file to be overwritten but not the content to be written into the file. Binary-Affected: podman Upstream-version-introduced: v4.0.0 Upstream-version-fixed: v5.6.1
References (32)
Core 32
Core References
Vendor Advisory vendor-advisory
x_refsource_redhat
RHSA-2026:8211
https://access.redhat.com/errata/RHSA-2026:8211
Vendor Advisory vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHBA-2025:15692
Vendor Advisory vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHBA-2025:15712
Vendor Advisory vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHBA-2025:16158
Vendor Advisory vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHBA-2025:16163
Vendor Advisory vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHEA-2025:4782
Vendor Advisory vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHSA-2025:15900
Vendor Advisory vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHSA-2025:15901
Vendor Advisory vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHSA-2025:15904
Vendor Advisory vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHSA-2025:16480
Vendor Advisory vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHSA-2025:16481
Vendor Advisory vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHSA-2025:16482
Vendor Advisory vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHSA-2025:16488
Vendor Advisory vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHSA-2025:16515
Vendor Advisory vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHSA-2025:16724
Vendor Advisory vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHSA-2025:17669
Vendor Advisory vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHSA-2025:18217
Vendor Advisory vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHSA-2025:18218
Vendor Advisory vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHSA-2025:18240
Vendor Advisory vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHSA-2025:19002
Vendor Advisory vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHSA-2025:19041
Vendor Advisory vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHSA-2025:19046
Vendor Advisory vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHSA-2025:19094
Vendor Advisory vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHSA-2025:19894
Vendor Advisory vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHSA-2025:20909
Vendor Advisory vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHSA-2025:20983
Vendor Advisory vendor-advisory
x_refsource_redhat
RHSA-2026:18289
https://access.redhat.com/errata/RHSA-2026:18289
Vendor Advisory vendor-advisory
x_refsource_redhat
RHSA-2026:18722
https://access.redhat.com/errata/RHSA-2026:18722
Vendor Advisory vdb-entry
x_refsource_redhat
https://access.redhat.com/security/cve/CVE-2025-9566
Issue Tracking issue-tracking
x_refsource_redhat
https://bugzilla.redhat.com/show_bug.cgi?id=2393152
Scores
CVSS v3
8.1
EPSS
0.0101
EPSS Percentile
58.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-22
Status
published
Products (50)
containers/podman
0 - 4.9.5Go
containers/podman
0 - 5.6.1Go
Red Hat/Red Hat Enterprise Linux 10
6:5.4.0-13.el10_0
Red Hat/Red Hat Enterprise Linux 10
7:5.6.0-5.el10_1
Red Hat/Red Hat Enterprise Linux 10
7:5.8.0-2.el10
Red Hat/Red Hat Enterprise Linux 8
8100020250911075811.afee755d
Red Hat/Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
8060020250919150821.3b538bd8
Red Hat/Red Hat Enterprise Linux 8.6 Telecommunications Update Service
8060020250919150821.3b538bd8
Red Hat/Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
8060020250919150821.3b538bd8
Red Hat/Red Hat Enterprise Linux 8.8 Telecommunications Update Service
8080020250919060528.0f77c1b7
... and 40 more
Published
Sep 05, 2025
Tracked Since
Feb 18, 2026