CVE-2025-11395: Red Hat Enterprise Linux 10

Medium severity, CVSS 5.5. EPSS: 0.4% chance of exploitation in the next 30 days.

A flaw was found in Podman. If an attacker can pass a crafted tar archive to the `podman load` command, they can create files on the host machine with the privileges of the user running Podman.

Affected products

  • Red Hat Red Hat Enterprise Linux 10
  • Red Hat Red Hat Enterprise Linux 8
  • Red Hat Red Hat Enterprise Linux 9: before 2:1.43.3-2.el9_8 (fixed in 2:1.43.3-2.el9_8); before 2:1.22.2-8.el9_8 (fixed in 2:1.22.2-8.el9_8)
  • Red Hat Red Hat Hardened Images
  • Red Hat Red Hat Openshift Container Platform 4
  • Red Hat Red Hat Openshift Dev Spaces

Published 2026-09-15. Last modified 2026-09-29.