Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-4953

Опубликовано: 16 сент. 2025
Источник: debian
EPSS Низкий

Описание

A flaw was found in Podman. In a Containerfile or Podman, data written to RUN --mount=type=bind mounts during the podman build is not discarded. This issue can lead to files created within the container appearing in the temporary build context directory on the host, leaving the created files accessible.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
podmanfixed5.3.2+ds1-1package
libpodremovedpackage
libpodno-dsabookwormpackage
libpodpostponedbullseyepackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=2367235

  • Fixed in podman by bumping/tighening the dependency on buildah up to the

  • version fixing CVE-2024-11218 and CVE-2024-9675. This is tricky to track

  • properly as we need to bump the dependency and rebuild to address the issue.

  • Details in: https://bugs.debian.org/1117966#22

EPSS

Процентиль: 20%
0.00063
Низкий

Связанные уязвимости

CVSS3: 7.4
ubuntu
3 месяца назад

A flaw was found in Podman. In a Containerfile or Podman, data written to RUN --mount=type=bind mounts during the podman build is not discarded. This issue can lead to files created within the container appearing in the temporary build context directory on the host, leaving the created files accessible.

CVSS3: 7.4
redhat
3 месяца назад

A flaw was found in Podman. In a Containerfile or Podman, data written to RUN --mount=type=bind mounts during the podman build is not discarded. This issue can lead to files created within the container appearing in the temporary build context directory on the host, leaving the created files accessible.

CVSS3: 7.4
nvd
3 месяца назад

A flaw was found in Podman. In a Containerfile or Podman, data written to RUN --mount=type=bind mounts during the podman build is not discarded. This issue can lead to files created within the container appearing in the temporary build context directory on the host, leaving the created files accessible.

msrc
17 дней назад

Podman: build context bind mount

CVSS3: 7.4
github
3 месяца назад

Podman Creates Temporary File with Insecure Permissions

EPSS

Процентиль: 20%
0.00063
Низкий