Executive brief
A security flaw was identified in Podman, a tool used for managing and building software containers. During the container building process, certain temporary data that should be discarded is instead saved to the host computer's temporary directories. This could allow sensitive files created inside a container during its build phase to be accessed by unauthorized users or processes on the host system.
Technical details
A vulnerability exists in Podman where data written to 'RUN --mount=type=bind' mounts during a 'podman build' operation is not properly discarded. This root cause leads to files created within the container environment persisting in the temporary build context directory on the host machine. An attacker with access to the host's temporary directories could retrieve sensitive information or files generated during the build process. The issue is categorized as an insecure temporary file creation (CWE-378). Patches have been released across various Red Hat products and the upstream Podman repository (commit 50295e5e5d1a4583d26d5c6d5c0608cff498cc8d).
Affected products
- Red Hat Podman All versions prior to commit 50295e5e5d1a4583d26d5c6d5c0608cff498cc8d
- Red Hat Red Hat Enterprise Linux 8 container-tools:rhel8 prior to 8100020250911075811.afee755d
- Red Hat Red Hat OpenShift Container Platform 4.12 podman prior to 3:4.2.0-15.rhaos4.12.el9
- Red Hat Red Hat OpenShift Container Platform 4.13 buildah prior to 1:1.29.1-5.rhaos4.13.el9
Timeline
- 2024-11-06: advisory: Initial Red Hat advisory (RHSA-2024:8690) published
- 2025-09-16: disclosed: CVE-2025-4953 details published to NVD
References
- https://github.com/containers/podman/
- https://access.redhat.com/downloads/content/package-browser/
- https://access.redhat.com/errata/RHSA-2024:8690
- https://access.redhat.com/errata/RHSA-2025:15904
- https://access.redhat.com/errata/RHSA-2025:16724
- https://access.redhat.com/errata/RHSA-2025:16729
- https://access.redhat.com/errata/RHSA-2025:17669