Link following in Podman - CVE-2025-9566
Published: September 8, 2025 / Updated: June 18, 2026
Vulnerability details
The vulnerability allows a malicious container to perform a denial of service (DoS) attack.
The vulnerability exists due to an insecure link following issue in podman kube play command. A malicious container can overwrite host files when the kube file contains a ConfigMap or Secret volume mount and the volume already contains a symlink to a host file.
Note, a malicious container can write to arbitrary files on the host BUT the attacker only controls the target path not the contents that will be written to the file.
Affected software
SUSE Multi-Linux Manager Server 5.1 Extension for
SUSE Multi-Linux Manager Retail Branch Server 5.1 Extension for
SUSE Multi-Linux Manager Proxy 5.1 Extension for
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
SUSE Enterprise Storage
Red Hat Enterprise Linux for IBM z Systems
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Containers Module
openSUSE Leap
Fedora
Netezza Appliance
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
toolbox-tests
toolbox
udica
containers-common
runc
slirp4netns
oci-seccomp-bpf-hook
containernetworking-plugins
aardvark-dns
netavark
fuse-overlayfs
crun
skopeo-tests
skopeo
buildah
buildah-tests
conmon
container-selinux
criu-libs
criu-devel
criu
python3-criu
crit
podman (Red Hat package)
libslirp
libslirp-devel
python3-podman
podman-tests
podman-docker
podman-remote
podman-plugins
podman-gvproxy
podman-catatonit
podman
podman-remote-debuginfo
podman-debuginfo
podmansh
cockpit-podman
Ansible Automation Platform
Red Hat OpenShift Dev Spaces
Multicluster Engine for Kubernetes
Red Hat OpenShift Container Platform
How to mitigate CVE-2025-9566
Netezza Appliance - update to 1.0.1.0 fp278500
toolbox-tests - update to 0.0.99.5-2.0.1
toolbox - update to 0.0.99.5-2.0.1
udica - update to 0.2.6-21
containers-common - addressed in versions 0.64.2-1.fc41, 0.64.2-1.fc42, 0.64.2-1.fc43
runc - update to 1.1.12-6.0.1
slirp4netns - update to 1.2.3-1
oci-seccomp-bpf-hook - update to 1.2.10-1
containernetworking-plugins - update to 1.4.0-6.0.1
aardvark-dns - update to 1.10.1-2.0.1
netavark - update to 1.10.3-1.0.1
fuse-overlayfs - update to 1.13-1.0.1
crun - update to 1.14.3-2
skopeo-tests - update to 1.14.5-4.0.1
skopeo - update to 1.14.5-4.0.1
buildah - update to 1.33.12-2
buildah-tests - update to 1.33.12-2
buildah - addressed in versions 1.41.4-1.fc41, 1.41.4-1.fc42, 1.41.4-1.fc43
containers-common - update to 1-82.0.1
conmon - update to 2.1.10-1
Ansible Automation Platform - update to 2.4
Multicluster Engine for Kubernetes - update to 2.7.6
container-selinux - update to 2.229.0-2
criu-libs - update to 3.18-5.0.1
criu-devel - update to 3.18-5.0.1
criu - update to 3.18-5.0.1
python3-criu - update to 3.18-5.0.1
crit - update to 3.18-5.0.1
Red Hat OpenShift Dev Spaces - update to 3.24.0
podman (Red Hat package) - addressed in versions 4.2.0-6.el9_0.5, 4.4.1-22.el9_2.4, 4.9.4-18.el9_4.3, 5.4.0-13.el9_6, 5.4.0-13.el10_0, 5.6.0-6.el9_7
libslirp - update to 4.4.0-2
libslirp-devel - update to 4.4.0-2
python3-podman - update to 4.9.0-3
podman-tests - update to 4.9.4-23.0.1
podman-docker - update to 4.9.4-23.0.1
podman-remote - update to 4.9.4-23.0.1
podman-plugins - update to 4.9.4-23.0.1
podman-gvproxy - update to 4.9.4-23.0.1
podman-catatonit - update to 4.9.4-23.0.1
podman - update to 4.9.4-23.0.1
podman-docker - addressed in versions 4.9.5-150300.9.55.1, 4.9.5-150400.4.53.1, 4.9.5-150500.3.49.1
podman - addressed in versions 4.9.5-150300.9.55.1, 4.9.5-150400.4.53.1, 4.9.5-150500.3.49.1
podman-remote - addressed in versions 4.9.5-150300.9.55.1, 4.9.5-150400.4.53.1, 4.9.5-150500.3.49.1
podman-remote-debuginfo - addressed in versions 4.9.5-150300.9.55.1, 4.9.5-150400.4.53.1, 4.9.5-150500.3.49.1
podman-debuginfo - addressed in versions 4.9.5-150300.9.55.1, 4.9.5-150400.4.53.1, 4.9.5-150500.3.49.1
podmansh - addressed in versions 4.9.5-150300.9.55.1, 4.9.5-150400.4.53.1, 4.9.5-150500.3.49.1
Red Hat OpenShift Container Platform - addressed in versions 4.12.82, 4.13.61, 4.14.58, 4.17.42, 4.18.27, 4.19.17, 4.20.1
podman - addressed in versions 5.6.1-1.fc41, 5.6.1-1.fc42, 5.6.1-1.fc43
cockpit-podman - update to 84.1-1
External References
- https://bugzilla.redhat.com/show_bug.cgi?id=2393152
- https://github.com/containers/podman/commit/43fbde4e665fe6cee6921868f04b7ccd3de5ad89
- https://github.com/containers/podman/security/advisories/GHSA-wp3j-xq48-xpjw
- https://github.com/podman-container-tools/podman/security/advisories/GHSA-wp3j-xq48-xpjw
Related Security Bulletins
- Denial of service in Podman
- Fedora 41 update for buildah, containers-common, podman
- Fedora 42 update for buildah, containers-common, podman
- Fedora 43 update for buildah, containers-common, podman
- Red Hat Enterprise Linux 10 update for podman
- Red Hat Enterprise Linux 8 update for the container-tools:rhel8 module
- Anolis OS update for container-tools:an8 module
- Multiple vulnerabilities in Ansible Automation Platform 2.4 packages
- Red Hat Enterprise Linux 9 update for podman
- Red Hat Enterprise Linux 8 update for the container-tools:rhel8 module
- Red Hat Enterprise Linux 9 update for podman
- Red Hat Enterprise Linux 9 update for podman
- Red Hat Enterprise Linux 9 update for podman
- SUSE update for podman
- SUSE update for podman
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.7
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.19
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- SUSE update for podman
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.18
- Link following in Red Hat OpenShift Container Platform 4.20
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Dev Spaces
- Red Hat Enterprise Linux 8 update for the container-tools:rhel8 module
- Red Hat Enterprise Linux 9 update for podman
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Multiple vulnerabilities in IBM Netezza Appliance