在 Podman 中发现了一个漏洞。如果攻击者能够将一个精心构造的 tar 归档文件传递给 命令,他们就可以以运行 Podman 的用户权限在主机上创建文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| Red Hat | Red Hat Hardened Images | - |
cpe:/a:redhat:hummingbird:1
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| Red Hat | Red Hat OpenShift Dev Spaces | - |
cpe:/a:redhat:openshift_devspaces:3
|
|
| Red Hat | Red Hat OpenShift Dev Spaces | - |
cpe:/a:redhat:openshift_devspaces:3
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-92248 | 7.8 HIGH | Gimp: integer overflow when generating a thumbnail preview for a psd file |
| CVE-2026-85234 | 7.5 HIGH | Tftp: tftp-hpa: denial of service due to out-of-bounds read/write in remap engine |
| CVE-2026-75092 | 7.3 HIGH | Leapp-repository: leapp-upgrade-el9toel10: leapp-upgrade-el9toel10: scan_mysql runs mysqld |
| CVE-2026-85013 | 7.3 HIGH | Environment-modules: command injection in environment-modules bash completion via maliciou |
| CVE-2026-81303 | 6.3 MEDIUM | Hawtio-operator: hawtio-operator: routes/custom-host confused-deputy via spec.routehostnam |
| CVE-2026-91786 | 6.1 MEDIUM | Gnome-shell: gnome-shell: out-of-bounds read in remote search icon rendering due to unvali |
| CVE-2026-81320 | 5.5 MEDIUM | Hawtio-operator: hawtio-operator: tls private key written to operator log at debug level |
| CVE-2026-79705 | 4.5 MEDIUM | Podman: buildah: buildah/copier: directory escape via crafted tar symlinks when used outsi |
| CVE-2026-79699 | 4.4 MEDIUM | Podman: buildah: skopeo: containers/storage: malicious tar whiteout header allows replacem |
| CVE-2026-91926 | 3.7 LOW | Gss-ntlmssp: gss-ntlmssp: memory leak in ntlm_decode_target_info via duplicated av_pair en |
No comments yet