podman: symlink exchange attack in podman export volume
Published Mar 27, 2023
6.8
MEDIUMCVSS 3.1
EPSS 0.54%
Description
A Time-of-check Time-of-use (TOCTOU) flaw was found in podman. This issue may allow a malicious user to replace a normal file in a volume with a symlink while exporting the volume, allowing for access to arbitrary files on the host file system.
Affected products
- Vendor n/a Product Podman Defaultunknown
Affected
- unknown
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| n/a | Podman | unknown | Affected
|
Configuration 1
- n/a
Configuration 2
- 8.0
- 9.0
No data.
Red Hat Enterprise Linux 8
container-tools:4.0-8080020230217080101.8108cfbc
Fixed · RHSA-2023:2802
Red Hat Enterprise Linux 8
container-tools:rhel8-8080020230321153727.0f77c1b7
Fixed · RHSA-2023:2758
Red Hat OpenShift Container Platform 4.13
podman-3:4.4.1-3.rhaos4.13.el8
Fixed · RHSA-2023:1325
Red Hat Enterprise Linux 7
podman
Out of support scope
Red Hat Enterprise Linux 8
container-tools:3.0/podman
Not affected
Red Hat Enterprise Linux 9
podman
Affected
Red Hat OpenShift Container Platform 3.11
podman
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | container-tools:4.0-8080020230217080101.8108cfbc | Fixed | RHSA-2023:2802 |
| Red Hat Enterprise Linux 8 | container-tools:rhel8-8080020230321153727.0f77c1b7 | Fixed | RHSA-2023:2758 |
| Red Hat OpenShift Container Platform 4.13 | podman-3:4.4.1-3.rhaos4.13.el8 | Fixed | RHSA-2023:1325 |
| Red Hat Enterprise Linux 7 | podman | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | container-tools:3.0/podman | Not affected | n/a |
| Red Hat Enterprise Linux 9 | podman | Affected | n/a |
| Red Hat OpenShift Container Platform 3.11 | podman | Out of support scope | n/a |
github.com/containers/podman/v4
Go
Introduced 0 Fixed 4.4.2
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/containers/podman/v4 | 0 | 4.4.2 |
Remediation
No remediation recorded yet.
References (10)
- https://access.redhat.com/security/cve/CVE-2023-0778 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2168256 Issue TrackingThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-1087 Advisory
- https://github.com/advisories/GHSA-qwqv-rqgf-8qh8 Advisory
- https://github.com/containers/podman/commit/6ca857feb07a5fdc96fd947afef03916291673d8
- https://github.com/containers/podman/pull/17528
- https://github.com/containers/podman/pull/17532
- https://nvd.nist.gov/vuln/detail/CVE-2023-0778
- https://pkg.go.dev/vuln/GO-2023-1681
- https://www.cve.org/CVERecord?id=CVE-2023-0778
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub