Source: podman Version: 5.6.2+ds1-3 Severity: important Tags: security upstream X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi Reinhard, The following vulnerability was published for podman. CVE-2025-4953[0]: | A flaw was found in Podman. In a Containerfile or Podman, data | written to RUN --mount=type=bind mounts during the podman build is | not discarded. This issue can lead to files created within the | container appearing in the temporary build context directory on the | host, leaving the created files accessible. There is not much information (or at least I have not found it), neither in github issues or pull requests. The only reference we have is right now the Red Hat bugzilla entry referring to an issue import[1]. Could you try to find out more on it? If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2025-4953 https://www.cve.org/CVERecord?id=CVE-2025-4953 [1] https://bugzilla.redhat.com/show_bug.cgi?id=2367235 Please adjust the affected versions in the BTS as needed. Regards, Salvatore _______________________________________________ Pkg-go-maintainers mailing list [email protected] https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-go-maintainers
