cbcvebase.
CVE-2025-9566
published 2025-09-05

CVE-2025-9566: There's a vulnerability in podman where an attacker may use the kube play command to overwrite host files when the kube file container a Secrete or a ConfigMap…

PriorityP354high8.1CVSS 3.1
AVNACLPRLUINSUCNIHAH
EPSS
1.01%
59.1th percentile
There's a vulnerability in podman where an attacker may use the kube play command to overwrite host files when the kube file container a Secrete or a ConfigMap volume mount and such volume contains a symbolic link to a host file path. In a successful attack, the attacker can only control the target file to be overwritten but not the content to be written into the file. Binary-Affected: podman Upstream-version-introduced: v4.0.0 Upstream-version-fixed: v5.6.1

Affected

6 ranges
VendorProductVersion rangeFixed in
debianlibpod< podman 5.6.1+ds1-2 (forky)podman 5.6.1+ds1-2 (forky)
debianpodman< podman 5.6.1+ds1-2 (forky)podman 5.6.1+ds1-2 (forky)
github.comcontainers_podman_v40 – 4.9.5
github.comcontainers_podman_v5>= 0 < 5.6.15.6.1
msrcazl3_libcontainers-common_20240213-3_on_azure_linux_3.0
podman_projectpodman>= 0 < 5.6.1+ds1-25.6.1+ds1-2

CVSS provenance

nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
osv8.1HIGH
vendor_debian8.1HIGH
vendor_msrc8.1HIGH
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.