CVE-2025-11395

Published: September 20, 2026Last modified: October 7, 2026

Description

A flaw was found in Podman. If an attacker can pass a crafted tar archive to the `podman load` command, they can create files on the host machine with the privileges of the user running Podman.

Severity score breakdown

ParameterValue
Base score5.5
Attack VectorADJACENT_NETWORK
Attack complexityLOW
Privileges requiredLOW
User interactionNONE
ScopeUNCHANGED
ConfidentialityLOW
Integrity impactLOW
Availability impactLOW
VectorCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSpodmanUnknown (4.3.1-r0)
25 LTSpodmanUnknown (5.5.0-r0)
StreampodmanFixed (6.1.3-r0)
skopeoFixed (1.24.1-r0)

References

ON THIS PAGE