podman: Containers run as non-root users do not drop capabilities
Published Jul 2, 2018
8.7
HIGHCVSS 4.0
EPSS 0.88%
Description
It has been discovered that podman before version 0.6.1 does not drop capabilities when executing a container as a non-root user. This results in unnecessary privileges being granted to the container.
Affected products
- Vendor n/a Product Podman Defaultn/a
- Version podman 0.6.1StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Podman | n/a |
|
- < 0.6.1
No data.
Red Hat Enterprise Linux 7 Extras
podman-0:0.6.1-3.git3e0ff12.el7
Fixed · RHSA-2018:2037
Red Hat Enterprise Linux 8
podman
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 Extras | podman-0:0.6.1-3.git3e0ff12.el7 | Fixed | RHSA-2018:2037 |
| Red Hat Enterprise Linux 8 | podman | Not affected | n/a |
github.com/containers/podman
Go
Introduced 0 Fixed 0.6.1github.com/containers/podman/v3
Go
Introduced 0 Fixed not fixedgithub.com/containers/podman/v4
Go
Introduced 0 Fixed not fixedgithub.com/containers/podman/v2
Go
Introduced 0 Fixed not fixed
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/containers/podman | 0 | 0.6.1 |
| Go | github.com/containers/podman/v3 | 0 | not fixed |
| Go | github.com/containers/podman/v4 | 0 | not fixed |
| Go | github.com/containers/podman/v2 | 0 | not fixed |
Remediation
No remediation recorded yet.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
1 other source (Red Hat) ▾
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
AV:N/AC:L/Au:S/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Table of values (10 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 0.88% (0.00878) | 57.65th | v5 (v2026.06.15) |
| Sep 20, 2026 | 0.88% (0.00878) | 57.49th | v5 (v2026.06.15) |
| Jul 20, 2024 | 0.19% (0.00194) | 57.40th | v3 (v2023.03.01) |
| Nov 23, 2023 | 0.19% (0.00194) | 57.21th | v3 (v2023.03.01) |
| Nov 3, 2023 | 0.19% (0.00187) | 56.08th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.19% (0.00186) | 54.07th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.89% (0.00890) | 30.33th | v2 (v2022.01.01) |
| Feb 4, 2022 | 0.89% (0.00890) | 12.04th | v2 (v2022.01.01) |
| Feb 3, 2022 | 0.83% (0.00833) | 24.58th | v5 (v2026.06.15) |
| Apr 14, 2021 | 0.83% (0.00833) | 0.00th | v1 |
References (8)
- https://access.redhat.com/errata/RHSA-2018:2037 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2018-10856 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1592166 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10856 x_refsource_CONFIRMIssue TrackingThird Party Advisory
- https://github.com/advisories/GHSA-wp7w-vx86-vj9h Advisory
- https://github.com/projectatomic/libpod/commit/bae80a0b663925ec751ad2784ca32989403cdc24 x_refsource_CONFIRMPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-10856
- https://www.cve.org/CVERecord?id=CVE-2018-10856
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2018:2037 | vendor-advisoryx_refsource_REDHATThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2018-10856 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1592166 | Issue Tracking | |
| https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10856 | x_refsource_CONFIRMIssue TrackingThird Party Advisory | |
| https://github.com/advisories/GHSA-wp7w-vx86-vj9h | Advisory | |
| https://github.com/projectatomic/libpod/commit/bae80a0b663925ec751ad2784ca32989403cdc24 | x_refsource_CONFIRMPatchThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2018-10856 | ||
| https://www.cve.org/CVERecord?id=CVE-2018-10856 |
Change history (0)
No recorded changes yet.