CVE-2025-4953

EUVD-2025-29612
A flaw was found in Podman. In a Containerfile or Podman, data written to RUN --mount=type=bind mounts during the podman build is not discarded. This issue can lead to files created within the container appearing in the temporary build context directory on the host, leaving the created files accessible.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.4 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 47.92%
Debian logo
Debian Releases
Debian Product
Codename
libpod
bookworm
no-dsa
bullseye
postponed
podman
forky
5.8.3+ds1-1
fixed
sid
5.8.3+ds1-1
fixed
trixie
5.4.2+ds1-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
podman
jammy
dne
noble
dne
plucky
ignored
questing
ignored
resolute
needs-triage
libpod
jammy
needs-triage
noble
needs-triage
plucky
dne
questing
dne
resolute
dne
Azure Linux logo
Azure Linux Releases
Azure Package
Release
podman
Azure Linux 3.0
0:5.6.1-2.azl3
fixed