Back

MEDIUM

Podman: buildah: buildah/copier: directory escape via crafted tar symlinks when used outside buildah by non-root callers

Published Sep 15, 2026

Description

A flaw was found in the buildah/copier Go package. When used outside of Buildah by a non-root caller, a crafted tar archive containing malicious symlinks can escape the target extraction directory and create files outside the intended destination. Buildah itself uses chroot hardening and is not affected.

Affected products

Remediation

Vendor solution

To mitigate this issue, users should ensure that `podman cp` operations are only performed against trusted Podman system service servers. Copying content from untrusted sources may expose the client to directory traversal vulnerabilities.

Red Hat statement

This flaw allows a directory escape via crafted tar symlinks when a macOS Podman remote client performs `podman cp` against a malicious Podman system service server. Exploitation requires interaction with a malicious server and is not applicable to typical container deployments on Red Hat Enterprise Linux.

Red Hat mitigation

To mitigate this issue, users should ensure that `podman cp` operations are only performed against trusted Podman system service servers. Copying content from untrusted sources may expose the client to directory traversal vulnerabilities.

Weaknesses (1)

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Sep 15, 2026
Updated Oct 2, 2026
Reserved Aug 25, 2026
CISA Vulnrichment
Updated Sep 15, 2026
NVD
Status Awaiting Analysis
Modified Oct 2, 2026
Red Hat
Severity Moderate
Public date Sep 15, 2026
ENISA EUVD
Assigner redhat
Published Sep 15, 2026
Updated Oct 2, 2026
Exploited since n/a
EUVD-2026-78823