---
id: CVE-2025-4953
title: A flaw was found in Podman
summary: >-
  A flaw was found in Podman. In a Containerfile or Podman, data written to RUN
  --mount=type=bind mounts during the podman build is not discarded. This issue
  can lead to files created within the container appearing in the temporary
  build c…
severity: high
cvss: 7.4
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-378
published: '2025-09-16'
updated: '2026-06-25'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-4953'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2024:8690'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:15904'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:16724'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:16729'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:17669'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:22265'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:22275'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:22695'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:22724'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:22732'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:23113'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:2703'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:0316'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2025-4953'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2367235'
    label: secalert@redhat.com
  - url: 'https://github.com/containers/podman/pull/25173'
    label: secalert@redhat.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-4953.json
  - url: 'https://www.cve.org/CVERecord?id=CVE-2025-4953'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2025-4953'
tags:
  - nvd
  - csaf
  - vex
  - red-hat
epss: 0.00639
epssPercentile: 0.49238
ingestedAt: '2026-06-29T13:24:34.560Z'
vendor: Red Hat
product: Red Hat OpenShift Container Platform 4.13
affected:
  - openshift_container_platform 4
  - openshift_container_platform 4.12
  - openshift_container_platform 4.13
  - openshift_container_platform 4.16
  - openshift_container_platform 4.18
  - openshift_container_platform 4.14
  - openshift_container_platform 4.15
  - openshift_container_platform 4.17
  - enterprise_linux_appstream_v_8
patched:
  - openshift_container_platform 4.12
  - openshift_container_platform 4.13
  - openshift_container_platform 4.16
  - openshift_container_platform 4.18
  - openshift_container_platform 4.14
  - openshift_container_platform 4.15
  - openshift_container_platform 4.17
  - enterprise_linux_appstream_v_8
---

## Overview

A flaw was found in Podman. In a Containerfile or Podman, data written to RUN --mount=type=bind mounts during the podman build is not discarded. This issue can lead to files created within the container appearing in the temporary build context directory on the host, leaving the created files accessible.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **RHSA-2025:17669** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.12 · released 2025-10-16 · [advisory](https://access.redhat.com/errata/RHSA-2025:17669)
- **RHSA-2026:0316** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.12 · released 2026-01-15 · [advisory](https://access.redhat.com/errata/RHSA-2026:0316)
- **RHSA-2025:2703** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.13 · released 2025-03-20 · [advisory](https://access.redhat.com/errata/RHSA-2025:2703)
- **RHSA-2024:8690** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.13 · released 2024-11-06 · [advisory](https://access.redhat.com/errata/RHSA-2024:8690)
- **RHSA-2025:16724** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.16 · released 2025-10-01 · [advisory](https://access.redhat.com/errata/RHSA-2025:16724)
- **RHSA-2025:16729** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.18 · released 2025-10-01 · [advisory](https://access.redhat.com/errata/RHSA-2025:16729)
- **RHSA-2025:22275** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.13 · released 2025-12-05 · [advisory](https://access.redhat.com/errata/RHSA-2025:22275)
- **RHSA-2025:22732** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.14 · released 2025-12-11 · [advisory](https://access.redhat.com/errata/RHSA-2025:22732)
- **RHSA-2025:23113** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.15 · released 2026-01-07 · [advisory](https://access.redhat.com/errata/RHSA-2025:23113)
- **RHSA-2025:22724** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.16 · released 2025-12-10 · [advisory](https://access.redhat.com/errata/RHSA-2025:22724)
- **RHSA-2025:22265** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.17 · released 2025-12-03 · [advisory](https://access.redhat.com/errata/RHSA-2025:22265)
- **Red Hat VEX** · Moderate · affected: Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat OpenShift Container Platform 4 · updated 2026-09-08 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-4953.json)
