A flaw was found in Podman. If an attacker can pass a crafted tar archive to the `podman load` command, they can create files on the host machine with the privileges of the user running Podman.

Project Subscriptions

Vendors Products
Enterprise Linux Subscribe
Hummingbird Subscribe
Openshift Subscribe
Openshift Devspaces Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

History

Tue, 15 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in Podman. If an attacker can pass a crafted tar archive to the `podman load` command, they can create files on the host machine with the privileges of the user running Podman.
Title Podman: arbitrary file write when importing oci archive
First Time appeared Redhat
Redhat enterprise Linux
Redhat hummingbird
Redhat openshift
Redhat openshift Devspaces
Weaknesses CWE-277
CPEs cpe:/a:redhat:hummingbird:1
cpe:/a:redhat:openshift:4
cpe:/a:redhat:openshift_devspaces:3
cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
Redhat hummingbird
Redhat openshift
Redhat openshift Devspaces
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-15T22:59:03.366Z

Reserved: 2025-10-07T03:14:35.482Z

Link: CVE-2025-11395

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-15T23:16:59.933

Modified: 2026-09-15T23:16:59.933

Link: CVE-2025-11395

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses