Input validation error in Podman - CVE-2026-79699
Published: September 18, 2026
Vulnerability details
The vulnerability allows a remote attacker to overwrite arbitrary local files outside of the extraction destination.
The vulnerability exists due to improper input validation in storage/pkg/archive.{UnpackLayer,ApplyLayer,ApplyUncompressedLayer} when extracting a maliciously crafted tar archive. A remote attacker can supply a maliciously crafted tar archive to overwrite arbitrary local files outside of the extraction destination.
User interaction is required to extract the crafted archive.