A Time-of-check Time-of-use (TOCTOU) flaw was found in podman. This issue may allow a malicious user to replace a normal file in a volume with a symlink while exporting the volume, allowing for access to arbitrary files on the host file system.
{ "binaries": [ { "binary_version": "3.4.4+ds1-1ubuntu1.22.04.3", "binary_name": "podman" }, { "binary_version": "3.4.4+ds1-1ubuntu1.22.04.3", "binary_name": "podman-docker" } ] }
{ "binaries": [ { "binary_version": "4.9.3+ds1-1ubuntu0.2", "binary_name": "podman" }, { "binary_version": "4.9.3+ds1-1ubuntu0.2", "binary_name": "podman-docker" }, { "binary_version": "4.9.3+ds1-1ubuntu0.2", "binary_name": "podman-remote" } ] }