Impact
A flaw in Podman’s handling of OCI archives allows an attacker to supply a crafted tar file that, when processed by the podman load command, results in arbitrary file creation on the host with the privileges of the user running Podman. This may enable the placement of malicious configuration files, obscure evidence, or compromise binaries if the user has sufficient rights. The vulnerability is a classic authorization bypass through user‐controlled key (CWE‑277).
Affected Systems
The vulnerability affects several Red Hat products that include Podman, including Red Hat Enterprise Linux 8, 9, and 10, Red Hat Hardened Images, Red Hat OpenShift Container Platform 4, and Red Hat OpenShift Dev Spaces. Specific pending version information is not provided, implying that any installation employing Podman without a later patch may be impacted.
Risk and Exploitability
With a CVSS score of 5.5, the risk is moderate but not critical. The EPSS score of less than 1% indicates that exploitation is currently unlikely, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires an attacker who has the ability to run Podman commands to supply a malicious archive; no remote code execution is described, so the threat is primarily local and depends on the user’s privilege level. Nonetheless, the ability to write arbitrary files could be leveraged by a privileged user to mount subsequent attacks or exfiltrate data.
OpenCVE Enrichment