UNIX symbolic link following in Podman - CVE-2019-18466
Published: April 1, 2020
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a symlink following issue in libpod (podman) in the host context during a copy operation from the container to the
host, because an undesired glob operation occurs. An attacker could
create a container image containing particular symlinks that, when
copied by a victim user to the host filesystem, may overwrite existing
files with others from the host.
Successful exploitation of this vulnerability may result in privilege escalation on the host operating system.
Affected software
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Opensuse
podman (Red Hat package)
How to mitigate CVE-2019-18466
podman (Red Hat package) - update to 1.6.4-16.el7_8