Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-55686

Опубликовано: 26 июн. 2026
Источник: nvd
CVSS3: 5.3
EPSS Низкий

Описание

Podman is a tool for managing OCI containers and pods. From 3.0.0 until 5.7.1, running a malicious container image where the WORKDIR path contains a symlink can create a directory or modify ownership on the host filesystem. Modified ownership is less likely to happen as that requires help from an untrusted/malicious process that mutates the host filesystem tree during dereferencing of the WORKDIR path, to trigger a race condition. This vulnerability is fixed in 5.7.1.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:podman_project:podman:*:*:*:*:*:*:*:*
Версия от 3.0.0 (включая) до 5.7.1 (исключая)

EPSS

Процентиль: 24%
0.00317
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-61

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 1 месяца назад

Podman is a tool for managing OCI containers and pods. From 3.0.0 until 5.7.1, running a malicious container image where the WORKDIR path contains a symlink can create a directory or modify ownership on the host filesystem. Modified ownership is less likely to happen as that requires help from an untrusted/malicious process that mutates the host filesystem tree during dereferencing of the WORKDIR path, to trigger a race condition. This vulnerability is fixed in 5.7.1.

CVSS3: 5.8
redhat
около 1 месяца назад

Podman is a tool for managing OCI containers and pods. From 3.0.0 until 5.7.1, running a malicious container image where the WORKDIR path contains a symlink can create a directory or modify ownership on the host filesystem. Modified ownership is less likely to happen as that requires help from an untrusted/malicious process that mutates the host filesystem tree during dereferencing of the WORKDIR path, to trigger a race condition. This vulnerability is fixed in 5.7.1.

CVSS3: 5.3
debian
около 1 месяца назад

Podman is a tool for managing OCI containers and pods. From 3.0.0 unti ...

CVSS3: 5.3
github
около 2 месяцев назад

Podman: WORKDIR symlink traversal vulnerability

EPSS

Процентиль: 24%
0.00317
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-61