SB20260918103 - Multiple vulnerabilities in Podman
Published: September 18, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 3 vulnerabilities.
1) Path traversal (CVE-ID: CVE-2025-11395)
CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to overwrite attacker-chosen files and modify their attributes.
The vulnerability exists due to improper archive extraction in storage/pkg/archive when extracting a maliciously crafted tar archive. A remote attacker can provide a maliciously crafted tar archive to overwrite attacker-chosen files and modify their attributes.
User interaction is required to extract the crafted archive.
2) Input validation error (CVE-ID: CVE-2026-79699)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to overwrite arbitrary local files outside of the extraction destination.
The vulnerability exists due to improper input validation in storage/pkg/archive.{UnpackLayer,ApplyLayer,ApplyUncompressedLayer} when extracting a maliciously crafted tar archive. A remote attacker can supply a maliciously crafted tar archive to overwrite arbitrary local files outside of the extraction destination.
User interaction is required to extract the crafted archive.
3) Path traversal (CVE-ID: CVE-2026-79705)
CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to overwrite arbitrary local files.
The vulnerability exists due to improper file path handling in the buildah/copier Go package when extracting maliciously crafted tar archives. A remote attacker can provide a maliciously crafted tar archive to overwrite arbitrary local files.
The issue is limited to uses outside the Buildah codebase by non-root or non-Linux users.
Remediation
Install update from vendor's website.
References
- https://github.com/podman-container-tools/container-libs/security/advisories/GHSA-3gcv-x57j-xqxv
- https://github.com/containers/libpod/releases/tag/v6.1.2
- https://github.com/podman-container-tools/container-libs/commit/acbb1e7d4c83af744231fb61c61f9a9da2cf62b2
- https://github.com/podman-container-tools/container-libs/security/advisories/GHSA-mmq6-9mjh-hvq3
- https://github.com/podman-container-tools/buildah/security/advisories/GHSA-3528-5p26-cf44
- https://github.com/containers/buildah/commit/a88128d47cb3f3fcbd9e874270c22271b73eb30d