CVE-2025-9566 - CVE House
Back to Database
Status published High CVE-2025-9566

Podman: podman kube play command may overwrite host files

Vulnerability Description

There's a vulnerability in podman where an attacker may use the kube play command to overwrite host files when the kube file container a Secrete or a ConfigMap volume mount and such volume contains a symbolic link to a host file path. In a successful attack, the attacker can only control the target file to be overwritten but not the content to be written into the file. Binary-Affected: podman Upstream-version-introduced: v4.0.0 Upstream-version-fixed: v5.6.1

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-9566

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • This issue was discovered by Paul Holzinger (Red Hat).

References

Affected Vendor

Affected Software

Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.6 Telecommunications Update Service, Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.8 Telecommunications Update Service, Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions, Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions, Red Hat Enterprise Linux 9.4 Extended Update Support, Red Hat OpenShift Container Platform 4.12, Red Hat OpenShift Container Platform 4.13, Red Hat OpenShift Container Platform 4.14, Red Hat OpenShift Container Platform 4.15, Red Hat OpenShift Container Platform 4.16, Red Hat OpenShift Container Platform 4.17, Red Hat OpenShift Container Platform 4.18, Red Hat OpenShift Container Platform 4.19, Red Hat OpenShift Container Platform 4.20, Red Hat Hardened Images, Red Hat OpenShift Dev Spaces (RHOSDS) 3.24, Red Hat OpenShift Container Platform 4
Vulnerable Versions:
4.0.0, 6:5.4.0-13.el10_0, 7:5.6.0-5.el10_1, 7:5.8.0-2.el10, 8100020250911075811.afee755d, 8060020250919150821.3b538bd8, 8080020250919060528.0f77c1b7, 5:5.4.0-13.el9_6, 6:5.6.0-6.el9_7, 6:5.8.0-1.el9, 2:4.2.0-6.el9_0.5, 2:4.4.1-22.el9_2.4, 4:4.9.4-18.el9_4.3, 0:4.18.0-372.164.1.el8_6, 0:4.18.0-372.164.1.rt7.325.el8_6, 3:4.2.0-15.rhaos4.12.el9, 412.86.202510291903-0, 413.92.202510150118-0, 0:5.14.0-284.138.1.el9_2, 0:5.14.0-284.138.1.rt14.423.el9_2, 3:4.4.1-23.rhaos4.14.el8, 414.92.202510211419-0, 3:4.4.1-35.rhaos4.15.el8, 4:2.237.0-2.rhaos4.16.el9, 0:4.16.0-202509111927.p2.gf3d9123.assembly.stream.el8, 4:4.9.4-16.rhaos4.16.el8, 417.94.202510112152-0, 4:2.237.0-1.rhaos4.18.el9, 0:1.31.12-3.rhaos4.18.gitdc59c78.el8, 0:5.14.0-427.87.1.el9_4, 0:4.18.0-202509090932.p2.ga4cad44.assembly.stream.el8, 0:4.18.0-202509011551.p2.g018e43a.assembly.stream.el8, 5:5.2.2-11.rhaos4.18.el9, 418.94.202510230424-0, 4:2.237.0-1.rhaos4.19.el9, 0:1.32.8-3.rhaos4.19.git60d4e21.el9, 0:4.19.0-202509070341.p2.gb5229e8.assembly.stream.el9, 5:5.4.0-7.rhaos4.19.el9, 4.19.9.6.202510140714-0, 5:5.4.0-12.rhaos4.20.el9, 4.20.9.6.202510220229-0, 5.8.2-1.hum1, 3.24-1760921292, 3.24-1761160160

Timeline

Official Publish: September 5th, 2025
Last Modified: July 2nd, 2026
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

Weaknesses (CWE)