Database/Container, Kubernetes & orchestration
Podman: kube play follows symlinks in Secret/ConfigMap volumes and overwrites host files
Impact
A crafted Kubernetes YAML played on a node can point a Secret or ConfigMap volume at a symlink resolving to a host path, and podman writes through it. The attacker chooses which file gets clobbered but not the contents, so the realistic outcome is destroying host state rather than planting a backdoor: a CDI spec under /etc/cdi, a driver systemd unit, a kubelet or runtime config. On a GPU node that is enough to make the node stop presenting its accelerators or fail to come back cleanly after a restart, and the fix path is a package upgrade rather than anything you can undo in place. Introduced in podman v4.0.0 and fixed upstream in v5.6.1.
Who can reach it
Any user who can get a Kubernetes YAML played by podman kube play on the host. Authenticated, but no root required (PR:L, no user interaction).
What to do
Upgrade podman to 5.6.1 or the corresponding RHEL erratum build for your release. Package upgrade only: existing containers keep running, but restart any long-lived podman-managed services after the swap. No node reboot required.
References
Related entries
- Moby: plugin privilege approval can be bypassed during docker plugin installCVE-2026-33997 · Moby / Docker Engine daemon (docker plugin install privilege comparison)High
- Argo Workflows (controller, hostNetwork / securityContext / serviceAccountName merge path): The first fix forCVE-2026-42296 · Argo Workflows (controller, hostNetwork / securityContext / serviceAccountName merge path)High
- containerd: On SELinux hosts, an unprivileged pod with a hostPath volume can gain full read/write to the host filesystemCVE-2021-43816 · containerdHigh
- Cilium: IPsec transparent encryption is cryptographically ineffectiveCVE-2024-28860 · CiliumHigh
- Nuclio controller: cron trigger headers and body are injected into the CronJob shell commandCVE-2026-52831 · Nuclio controller (cron trigger rendered into Kubernetes CronJob args)High
- Strimzi Cluster Operator: attacker-set watchedNamespace grants Secret read/write in other namespacesCVE-2026-55225 · Strimzi Kafka Operator (Cluster Operator, Kafka.spec.entityOperator.watchedNamespace)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.