Vulnerability CVE-2023-0778: Information

Description

A Time-of-check Time-of-use (TOCTOU) flaw was found in podman. This issue may allow a malicious user to replace a normal file in a volume with a symlink while exporting the volume, allowing for access to arbitrary files on the host file system.

Severity: MEDIUM (6.8) Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N

Published: March 28, 2023
Modified: April 3, 2023
Error type identifier: CWE-367

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
podmansisyphus4.4.2-alt15.0.2-alt1.1ALT-PU-2023-1353-1315918Fixed
podmansisyphus_riscv644.4.2-alt15.0.2-alt1.1ALT-PU-2023-2734-1-Fixed
podmanp104.4.2-alt14.9.4-alt0.p10ALT-PU-2023-1488-1315926Fixed
podmanc10f14.4.2-alt14.4.4-alt1ALT-PU-2023-1488-1315926Fixed

References to Advisories, Solutions, and Tools

Hyperlink
Resource
https://bugzilla.redhat.com/show_bug.cgi?id=2168256
  • Issue Tracking
  • Third Party Advisory
    1. Configuration 1

      cpe:2.3:a:podman_project:podman:-:*:*:*:*:*:*:*

      Configuration 2

      cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*