Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-57231

Опубликовано: 26 июн. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Podman is a tool for managing OCI containers and pods. From 1.8.1 until 5.8.4, a container image that contains a environment variable with just a key and no value can trick podman into passing that variable from the host into the container. This is made worse by the fact that using an asterisk () will cause podman to pass all host variables into the container. So essentially a malicious image can exfiltrate all podman environment variables that are set in the session from where the container is launched. This vulnerability is fixed in 5.8.4 and 6.0.0.

A flaw was found in Podman, a tool for managing OCI containers and pods. A malicious container image can be crafted with an environment variable that has a key but no value, or an asterisk (
), to trick Podman. This vulnerability causes Podman to pass host environment variables into the container. Consequently, a malicious image could exfiltrate all Podman environment variables set in the session from which the container is launched, leading to information disclosure.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/eda-controller-rhel9Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-27/eda-controller-rhel9Not affected
Red Hat Enterprise Linux 10conmonNot affected
Red Hat Enterprise Linux 8conmonNot affected
Red Hat Enterprise Linux 8podmanAffected
Red Hat Enterprise Linux 9conmonNot affected
Red Hat OpenShift Container Platform 4conmonNot affected
Red Hat OpenShift Container Platform 4cri-oAffected
Red Hat OpenShift Container Platform 4kata-containersAffected
Red Hat OpenShift Container Platform 4rhcosAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-914
https://bugzilla.redhat.com/show_bug.cgi?id=2493620podman: Podman: Information disclosure via malicious container image environment variables

EPSS

Процентиль: 24%
0.00312
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 1 месяца назад

Podman is a tool for managing OCI containers and pods. From 1.8.1 until 5.8.4, a container image that contains a environment variable with just a key and no value can trick podman into passing that variable from the host into the container. This is made worse by the fact that using an asterisk (*) will cause podman to pass all host variables into the container. So essentially a malicious image can exfiltrate all podman environment variables that are set in the session from where the container is launched. This vulnerability is fixed in 5.8.4 and 6.0.0.

CVSS3: 7.5
nvd
около 1 месяца назад

Podman is a tool for managing OCI containers and pods. From 1.8.1 until 5.8.4, a container image that contains a environment variable with just a key and no value can trick podman into passing that variable from the host into the container. This is made worse by the fact that using an asterisk (*) will cause podman to pass all host variables into the container. So essentially a malicious image can exfiltrate all podman environment variables that are set in the session from where the container is launched. This vulnerability is fixed in 5.8.4 and 6.0.0.

msrc
около 1 месяца назад

Podman: Malformed Image can trick podman run into leaking host environment variables into the container

CVSS3: 7.5
debian
около 1 месяца назад

Podman is a tool for managing OCI containers and pods. From 1.8.1 unti ...

rocky
18 дней назад

Important: container-tools:rhel8 security update

EPSS

Процентиль: 24%
0.00312
Низкий

7.5 High

CVSS3