CVE-2025-9566: Red Hat Enterprise Linux 10
High severity, CVSS 8.1. EPSS: 1.1% chance of exploitation in the next 30 days.
There's a vulnerability in podman where an attacker may use the kube play command to overwrite host files when the kube file container a Secrete or a ConfigMap volume mount and such volume contains a symbolic link to a host file path. In a successful attack, the attacker can only control the target file to be overwritten but not the content to be written into the file. Binary-Affected: podman Upstream-version-introduced: v4.0.0 Upstream-version-fixed: v5.6.1
Affected products
- Red Hat Red Hat Enterprise Linux 10: before 6:5.4.0-13.el10_0 (fixed in 6:5.4.0-13.el10_0); before 7:5.6.0-5.el10_1 (fixed in 7:5.6.0-5.el10_1); before 7:5.8.0-2.el10 (fixed in 7:5.8.0-2.el10)
- Red Hat Red Hat Enterprise Linux 8: before 8100020250911075811.afee755d (fixed in 8100020250911075811.afee755d)
- Red Hat Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support: before 8060020250919150821.3b538bd8 (fixed in 8060020250919150821.3b538bd8)
- Red Hat Red Hat Enterprise Linux 8.6 Telecommunications Update Service: before 8060020250919150821.3b538bd8 (fixed in 8060020250919150821.3b538bd8)
- Red Hat Red Hat Enterprise Linux 8.6 Update Services For SAP Solutions: before 8060020250919150821.3b538bd8 (fixed in 8060020250919150821.3b538bd8)
- Red Hat Red Hat Enterprise Linux 8.8 Telecommunications Update Service: before 8080020250919060528.0f77c1b7 (fixed in 8080020250919060528.0f77c1b7)
- Red Hat Red Hat Enterprise Linux 8.8 Update Services For SAP Solutions: before 8080020250919060528.0f77c1b7 (fixed in 8080020250919060528.0f77c1b7)
- Red Hat Red Hat Enterprise Linux 9: before 5:5.4.0-13.el9_6 (fixed in 5:5.4.0-13.el9_6); before 6:5.6.0-6.el9_7 (fixed in 6:5.6.0-6.el9_7); before 6:5.8.0-1.el9 (fixed in 6:5.8.0-1.el9)
- Red Hat Red Hat Enterprise Linux 9.0 Update Services For SAP Solutions: before 2:4.2.0-6.el9_0.5 (fixed in 2:4.2.0-6.el9_0.5)
- Red Hat Red Hat Enterprise Linux 9.2 Update Services For SAP Solutions: before 2:4.4.1-22.el9_2.4 (fixed in 2:4.4.1-22.el9_2.4)
- Red Hat Red Hat Enterprise Linux 9.4 Extended Update Support: before 4:4.9.4-18.el9_4.3 (fixed in 4:4.9.4-18.el9_4.3)
- Red Hat Red Hat Hardened Images: before 5.8.2-1.hum1 (fixed in 5.8.2-1.hum1)
- Red Hat Red Hat Openshift Container Platform 4.12: before 412.86.202510291903-0 (fixed in 412.86.202510291903-0)
- Red Hat Red Hat Openshift Container Platform 4.13: before 413.92.202510150118-0 (fixed in 413.92.202510150118-0)
- Red Hat Red Hat Openshift Container Platform 4.14: before 0:5.14.0-284.138.1.el9_2 (fixed in 0:5.14.0-284.138.1.el9_2); before 0:5.14.0-284.138.1.rt14.423.el9_2 (fixed in 0:5.14.0-284.138.1.rt14.423.el9_2); before 3:4.4.1-23.rhaos4.14.el8 (fixed in 3:4.4.1-23.rhaos4.14.el8); before 414.92.202510211419-0 (fixed in 414.92.202510211419-0)
- Red Hat Red Hat Openshift Container Platform 4.15: before 0:5.14.0-284.138.1.el9_2 (fixed in 0:5.14.0-284.138.1.el9_2); before 0:5.14.0-284.138.1.rt14.423.el9_2 (fixed in 0:5.14.0-284.138.1.rt14.423.el9_2); before 3:4.4.1-35.rhaos4.15.el8 (fixed in 3:4.4.1-35.rhaos4.15.el8); before 415.92.202609140326-0 (fixed in 415.92.202609140326-0)
- Red Hat Red Hat Openshift Container Platform 4.16: before 416.94.202609011112-0 (fixed in 416.94.202609011112-0)
- Red Hat Red Hat Openshift Container Platform 4.17: before 417.94.202510112152-0 (fixed in 417.94.202510112152-0)
- Red Hat Red Hat Openshift Container Platform 4.18: before 4:2.237.0-1.rhaos4.18.el9 (fixed in 4:2.237.0-1.rhaos4.18.el9); before 0:1.31.12-3.rhaos4.18.gitdc59c78.el8 (fixed in 0:1.31.12-3.rhaos4.18.gitdc59c78.el8); before 0:5.14.0-427.87.1.el9_4 (fixed in 0:5.14.0-427.87.1.el9_4); before 0:4.18.0-202509090932.p2.ga4cad44.assembly.stream.el8 (fixed in 0:4.18.0-202509090932.p2.ga4cad44.assembly.stream.el8); before 0:4.18.0-202509011551.p2.g018e43a.assembly.stream.el8 (fixed in 0:4.18.0-202509011551.p2.g018e43a.assembly.stream.el8); before 5:5.2.2-11.rhaos4.18.el9 (fixed in 5:5.2.2-11.rhaos4.18.el9); …
- Red Hat Red Hat Openshift Container Platform 4.19: before 4:2.237.0-1.rhaos4.19.el9 (fixed in 4:2.237.0-1.rhaos4.19.el9); before 0:1.32.8-3.rhaos4.19.git60d4e21.el9 (fixed in 0:1.32.8-3.rhaos4.19.git60d4e21.el9); before 0:4.19.0-202509070341.p2.gb5229e8.assembly.stream.el9 (fixed in 0:4.19.0-202509070341.p2.gb5229e8.assembly.stream.el9); before 5:5.4.0-7.rhaos4.19.el9 (fixed in 5:5.4.0-7.rhaos4.19.el9); before 4.19.9.6.202510140714-0 (fixed in 4.19.9.6.202510140714-0)
- Red Hat Red Hat Openshift Container Platform 4.20: before 5:5.4.0-12.rhaos4.20.el9 (fixed in 5:5.4.0-12.rhaos4.20.el9); before 4.20.9.6.202510220229-0 (fixed in 4.20.9.6.202510220229-0)
- Red Hat Red Hat Openshift Dev Spaces Rhosds 3.24: before 3.24-1760921292 (fixed in 3.24-1760921292); before 3.24-1761160160 (fixed in 3.24-1761160160)
Published 2025-09-05. Last modified 2026-10-08.