Description
A Time-of-check Time-of-use (TOCTOU) flaw was found in podman. This issue may allow a malicious user to replace a normal file in a volume with a symlink while exporting the volume, allowing for access to arbitrary files on the host file system.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-1087 | A Time-of-check Time-of-use (TOCTOU) flaw was found in podman. This issue may allow a malicious user to replace a normal file in a volume with a symlink while exporting the volume, allowing for access to arbitrary files on the host file system. |
Github GHSA |
GHSA-qwqv-rqgf-8qh8 | Podman Time-of-check Time-of-use (TOCTOU) Race Condition |
References
History
Mon, 24 Feb 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-02-24T17:25:59.179Z
Reserved: 2023-02-10T00:00:00.000Z
Link: CVE-2023-0778
Updated: 2024-08-02T05:24:34.241Z
Status : Modified
Published: 2023-03-27T21:15:10.240
Modified: 2025-02-24T18:15:16.863
Link: CVE-2023-0778
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA