---
id: CVE-2025-9566
title: >-
  There's a vulnerability in podman where an attacker may use the kube play
  command to overwrite host files when the kube file container a Secrete or a
  ConfigMap volume mount and such volume contains a symbolic link to a host file
  path
summary: >-
  There's a vulnerability in podman where an attacker may use the kube play
  command to overwrite host files when the kube file container a Secrete or a
  ConfigMap volume mount and such volume contains a symbolic link to a host file
  path. In…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'
cwe:
  - CWE-22
  - CWE-61
vendor: Red Hat
product: podman
affected:
  - podman >= 4.0.0 < 5.6.1
  - podman (all versions)
  - podman (all versions)
  - podman (all versions)
  - 'container-tools:rhel8 (all versions)'
  - 'container-tools:rhel8 (all versions)'
  - 'container-tools:rhel8 (all versions)'
  - 'container-tools:rhel8 (all versions)'
  - 'container-tools:rhel8 (all versions)'
  - 'container-tools:rhel8 (all versions)'
  - podman (all versions)
  - podman (all versions)
  - podman (all versions)
  - podman (all versions)
  - podman (all versions)
  - podman (all versions)
  - rhcos (all versions)
  - rhcos (all versions)
  - kernel (all versions)
  - kernel-rt (all versions)
  - podman (all versions)
  - rhcos (all versions)
  - kernel (all versions)
  - kernel-rt (all versions)
  - podman (all versions)
  - rhcos (all versions)
  - rhcos (all versions)
  - container-selinux (all versions)
  - cri-o (all versions)
  - kernel (all versions)
  - openshift (all versions)
  - openshift-ansible (all versions)
  - podman (all versions)
  - rhcos (all versions)
  - container-selinux (all versions)
  - cri-o (all versions)
  - openshift (all versions)
  - podman (all versions)
  - rhcos (all versions)
  - podman (all versions)
  - rhcos (all versions)
  - podman-main (all versions)
  - devspaces/udi-base-rhel9 (all versions)
  - devspaces/udi-rhel9 (all versions)
  - openshift/ose-rhel-coreos-9 (all versions)
published: '2025-09-05'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T10:17:29.233'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-9566'
references:
  - url: 'https://access.redhat.com/errata/RHBA-2025:15692'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHBA-2025:15712'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHBA-2025:16158'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHBA-2025:16163'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHEA-2025:4782'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:15900'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:15901'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:15904'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:16480'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:16481'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:16482'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:16488'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:16515'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:16724'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:17669'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:18217'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:18218'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:18240'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:19002'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:19041'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:19046'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:19094'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:19894'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:20909'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:20983'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:18289'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:18722'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:62549'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:8211'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2025-9566'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2393152'
    label: secalert@redhat.com
  - url: >-
      https://github.com/containers/podman/commit/43fbde4e665fe6cee6921868f04b7ccd3de5ad89
    label: secalert@redhat.com
  - url: >-
      https://github.com/containers/podman/security/advisories/GHSA-wp3j-xq48-xpjw
    label: secalert@redhat.com
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2025-9566'
  - url: 'https://github.com/advisories/GHSA-wp3j-xq48-xpjw'
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-9566.json
  - url: 'https://www.cve.org/CVERecord?id=CVE-2025-9566'
tags:
  - nvd
  - cve.org
  - ghsa
  - go
  - csaf
  - vex
  - red-hat
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2025-09-05T20:16:38.360629Z'
epss: 0.0108
epssPercentile: 0.63181
ingestedAt: '2026-06-29T13:24:34.548Z'
aliases:
  - GHSA-wp3j-xq48-xpjw
ecosystem: go
patched:
  - github.com/containers/podman/v5 5.6.1
---

## Overview

There's a vulnerability in podman where an attacker may use the kube play command to overwrite host files when the kube file container a Secrete or a ConfigMap volume mount and such volume contains a symbolic link to a host file path. In a successful attack, the attacker can only control the target file to be overwritten but not the content to be written into the file.

Binary-Affected: podman
Upstream-version-introduced: v4.0.0
Upstream-version-fixed: v5.6.1

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2025-9566)

Affected packages:

- `github.com/containers/podman/v5 <= 5.6.0`
- `github.com/containers/podman/v4 <= 4.9.5`

Patched in:

- `github.com/containers/podman/v5 5.6.1`

Source: https://github.com/advisories/GHSA-wp3j-xq48-xpjw

## Vendor advisories

- **RHSA-2025:19894** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.12 · released 2025-11-13 · [advisory](https://access.redhat.com/errata/RHSA-2025:19894)
- **RHBA-2025:16163** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.14 · released 2025-09-25 · [advisory](https://access.redhat.com/errata/RHBA-2025:16163)
- **RHBA-2025:16158** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.15 · released 2025-09-25 · [advisory](https://access.redhat.com/errata/RHBA-2025:16158)
- **RHBA-2025:15712** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.18 · released 2025-09-17 · [advisory](https://access.redhat.com/errata/RHBA-2025:15712)
- **RHSA-2025:18240** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.13 · released 2025-10-23 · [advisory](https://access.redhat.com/errata/RHSA-2025:18240)
- **RHSA-2025:19041** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.14 · released 2025-10-30 · [advisory](https://access.redhat.com/errata/RHSA-2025:19041)
- **RHSA-2026:62549** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.16 · released 2026-09-10 · [advisory](https://access.redhat.com/errata/RHSA-2026:62549)
- **RHSA-2025:18218** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.17 · released 2025-10-22 · [advisory](https://access.redhat.com/errata/RHSA-2025:18218)
- **RHSA-2025:19046** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.18 · released 2025-10-29 · [advisory](https://access.redhat.com/errata/RHSA-2025:19046)
- **RHBA-2025:15692** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.19 · released 2025-09-16 · [advisory](https://access.redhat.com/errata/RHBA-2025:15692)
- **RHSA-2025:18217** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.19 · released 2025-10-22 · [advisory](https://access.redhat.com/errata/RHSA-2025:18217)
- **Red Hat VEX** · Important · affected: Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat OpenShift Container Platform 4 · updated 2026-09-10 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-9566.json)
