[CLSA-2025:1759505734] podman: Fix of CVE-2025-9566
Type:
security
Severity:
Important
Release date:
2025-10-03 15:35:46 UTC
Description:
- CVE-2025-9566: fix kube play vulnerability that allows following volume symlinks onto the host filesystem. Prevent symlink-based host escapes in ConfigMap and Secret volumes
Updated packages:
  • podman-4.4.1-13.el9_2.tuxcare.els4.x86_64.rpm
    sha:3d96da52c57ab8be36e0e3bb0f89fb2e6d26698df236ee5922c3aa199da1b7af
  • podman-docker-4.4.1-13.el9_2.tuxcare.els4.noarch.rpm
    sha:492935d7c69ef0aab5a132fef8b140e4dc5b0693930e71e8d1986d85c6019a44
  • podman-gvproxy-4.4.1-13.el9_2.tuxcare.els4.x86_64.rpm
    sha:2d789b659ac39eb9bfe4b1dacf25659205a4f71c7e387dfa96dc5bbb24087f53
  • podman-plugins-4.4.1-13.el9_2.tuxcare.els4.x86_64.rpm
    sha:204989ef83b51e16af139297818079500326a21b401bd74af3d65d1ddc00802e
  • podman-remote-4.4.1-13.el9_2.tuxcare.els4.x86_64.rpm
    sha:484c7a3e2101cbc5709ad9ba0218b2ca2f3ff8d5b5487f411b24b87ca034cb40
  • podman-tests-4.4.1-13.el9_2.tuxcare.els4.x86_64.rpm
    sha:4c67f3786aefb4030f213fb628dd0e060991860985ad7851baa0492661d7eec5
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.