Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-33414

Опубликовано: 14 апр. 2026
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

Podman is a tool for managing OCI containers and pods. Versions 4.8.0 through 5.8.1 contain a command injection vulnerability in the HyperV machine backend in pkg/machine/hyperv/stubber.go, where the VM image path is inserted into a PowerShell double-quoted string without sanitization, allowing $() subexpression injection. Because PowerShell evaluates subexpressions inside double-quoted strings before executing the outer command, an attacker who can control the VM image path through a crafted machine name or image directory can execute arbitrary PowerShell commands with the privileges of the Podman process. On typical Windows installations this means SYSTEM-level code execution, and only Windows is affected as the code is exclusive to the HyperV backend. This issue has been patched in version 5.8.2.

A flaw was found in Podman, a tool for managing containers. This vulnerability, located in the HyperV machine backend, allows for command injection. An attacker who can manipulate the virtual machine (VM) image path can inject and execute arbitrary PowerShell commands. This could lead to unauthorized system-level code execution on Windows installations where Podman is running.

Отчет

This flaw in Podman's HyperV backend does not affect Red Hat products. The vulnerable code path is exclusive to Windows installations, and the HyperV backend is not utilized on Red Hat Enterprise Linux or OpenShift Container Platform.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10podmanNot affected
Red Hat Enterprise Linux 8container-tools:rhel8/podmanNot affected
Red Hat Enterprise Linux 9podmanNot affected
Red Hat OpenShift Container Platform 4podmanNot affected
Red Hat OpenShift Container Platform 4rhcosNot affected
Red Hat Hardened Imagespodman-main-5.8.2-1.hum1FixedRHSA-2026:821114.04.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-94
https://bugzilla.redhat.com/show_bug.cgi?id=2458522podman: github.com/containers/podman: Podman: Arbitrary code execution via command injection in HyperV backend

EPSS

Процентиль: 45%
0.00607
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
4 месяца назад

Podman is a tool for managing OCI containers and pods. Versions 4.8.0 through 5.8.1 contain a command injection vulnerability in the HyperV machine backend in pkg/machine/hyperv/stubber.go, where the VM image path is inserted into a PowerShell double-quoted string without sanitization, allowing $() subexpression injection. Because PowerShell evaluates subexpressions inside double-quoted strings before executing the outer command, an attacker who can control the VM image path through a crafted machine name or image directory can execute arbitrary PowerShell commands with the privileges of the Podman process. On typical Windows installations this means SYSTEM-level code execution, and only Windows is affected as the code is exclusive to the HyperV backend. This issue has been patched in version 5.8.2.

CVSS3: 7.8
nvd
4 месяца назад

Podman is a tool for managing OCI containers and pods. Versions 4.8.0 through 5.8.1 contain a command injection vulnerability in the HyperV machine backend in pkg/machine/hyperv/stubber.go, where the VM image path is inserted into a PowerShell double-quoted string without sanitization, allowing $() subexpression injection. Because PowerShell evaluates subexpressions inside double-quoted strings before executing the outer command, an attacker who can control the VM image path through a crafted machine name or image directory can execute arbitrary PowerShell commands with the privileges of the Podman process. On typical Windows installations this means SYSTEM-level code execution, and only Windows is affected as the code is exclusive to the HyperV backend. This issue has been patched in version 5.8.2.

CVSS3: 7.8
debian
4 месяца назад

Podman is a tool for managing OCI containers and pods. Versions 4.8.0 ...

CVSS3: 7.8
github
4 месяца назад

PowerShell Command Injection in Podman HyperV Machine

EPSS

Процентиль: 45%
0.00607
Низкий

8.8 High

CVSS3