CVE-2025-4953

NameCVE-2025-4953
DescriptionA flaw was found in Podman. In a Containerfile or Podman, data written to RUN --mount=type=bind mounts during the podman build is not discarded. This issue can lead to files created within the container appearing in the temporary build context directory on the host, leaving the created files accessible.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1117966

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libpod (PTS)bullseye3.0.1+dfsg1-3+deb11u5vulnerable
bookworm4.3.1+ds1-8+deb12u1vulnerable
podman (PTS)trixie5.4.2+ds1-2fixed
forky, sid5.7.0+ds2-3fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libpodsource(unstable)(unfixed)
podmansource(unstable)5.3.2+ds1-11117966

Notes

[bookworm] - libpod <no-dsa> (Minor issue)
[bullseye] - libpod <postponed> (Minor issue)
https://bugzilla.redhat.com/show_bug.cgi?id=2367235
Fixed in podman by bumping/tighening the dependency on buildah up to the
version fixing CVE-2024-11218 and CVE-2024-9675. This is tricky to track
properly as we need to bump the dependency and rebuild to address the issue.
Details in: https://bugs.debian.org/1117966#22

Search for package or bug name: Reporting problems