CVE-2025-4953

high
Published 2025-09-16 · Modified 2026-02-04
CVSS v3
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS v2
VIR risk
8.0

Description

A flaw was found in Podman. In a Containerfile or Podman, data written to RUN --mount=type=bind mounts during the podman build is not discarded. This issue can lead to files created within the container appearing in the temporary build context directory on the host, leaving the created files accessible.

Predictions

Exploit likelihood
30%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2025-4953.html

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2025-4953

vendor Authored 2026-05-27

Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2025:15904

OS impact

OSVersionStatusFixed in
rockylinux rocky8fixed
debian debianbookwormaffected
debian debianbullseyeaffected
suse slesaffected
debian debianforkyfixed5.3.2+ds1-1
debian debiansidfixed5.3.2+ds1-1
debian debiantrixiefixed5.3.2+ds1-1

Package impact

EcosystemPackageVulnerableFixed
golang Gogithub.com/containers/podman/v5<=5.5.0
golang Gogithub.com/containers/podman
golang Gogithub.com/containers/podman/v2
golang Gogithub.com/containers/podman/v3
golang Gogithub.com/containers/podman/v4
golang Gogithub.com/containers/podman/v5

References

Verify integrity in audit chain (admin only). AS-IS.