Impact
A flaw in Podman’s handling of OCI archives allows an attacker to deliver a crafted tar file to the `podman load` command. When the archive is imported, the attacker can create files on the host file system with the privileges of the user running Podman. This permits the placement of arbitrary files that could influence configuration, obscure evidence, or potentially sabotage binaries if the user has sufficient rights.
Affected Systems
The vulnerability affects several Red Hat products that include Podman, including Red Hat Enterprise Linux 8, 9, and 10, Red Hat Hardened Images, Red Hat OpenShift Container Platform 4, and Red Hat OpenShift Dev Spaces. Specific pending version information is not provided, implying that any installation employing Podman without a later patch may be impacted.
Risk and Exploitability
With a CVSS score of 5.5, the risk is moderate but not critical. %, indicating that exploitation is currently unlikely, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires an attacker who has the ability to run Podman commands to supply a malicious archive; no remote code execution is described, so the threat is primarily local and depends on the user’s privilege level. Nonetheless, the ability to write arbitrary files could be leveraged by a privileged user to mount subsequent attacks or exfiltrate data.
OpenCVE Enrichment