Back

MEDIUM

podman: symlink exchange attack in podman export volume

Published Mar 27, 2023

Description

A Time-of-check Time-of-use (TOCTOU) flaw was found in podman. This issue may allow a malicious user to replace a normal file in a volume with a symlink while exporting the volume, allowing for access to arbitrary files on the host file system.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (10)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner redhat
Published Mar 27, 2023
Updated Feb 24, 2025
Reserved Feb 10, 2023

CISA Vulnrichment

Updated Feb 24, 2025

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Moderate
Public date Feb 15, 2023
Bugzilla 2168256

ENISA EUVD

Assigner redhat
Published Mar 27, 2023
Updated Feb 24, 2025