Medium severity5.5NVD Advisory· Published Oct 28, 2019· Updated Jun 17, 2026
CVE-2019-18466
CVE-2019-18466
Description
An issue was discovered in Podman in libpod before 1.6.0. It resolves a symlink in the host context during a copy operation from the container to the host, because an undesired glob operation occurs. An attacker could create a container image containing particular symlinks that, when copied by a victim user to the host filesystem, may overwrite existing files with others from the host.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/containers/podman/v4Go | < 1.6.0 | 1.6.0 |
Affected products
15- Podman/libpoddescription
- osv-coords13 versionspkg:rpm/opensuse/cni-plugins&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/conmon&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/fuse-overlayfs&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/podman&distro=openSUSE%20Leap%2015.1pkg:golang/github.com/containers/podman/v4pkg:rpm/suse/cni&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Containers%2015%20SP1pkg:rpm/suse/cni-plugins&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Containers%2015%20SP1pkg:rpm/suse/conmon&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Containers%2015%20SP1pkg:rpm/suse/fuse-overlayfs&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Containers%2015%20SP1pkg:rpm/suse/podman&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Containers%2015%20SP1pkg:rpm/suse/cni&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2015%20SP1pkg:rpm/suse/cni-plugins&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2015%20SP1pkg:rpm/opensuse/cni&distro=openSUSE%20Leap%2015.1
< 0.8.4-lp151.2.3.1+ 12 more
- (no CPE)range: < 0.8.4-lp151.2.3.1
- (no CPE)range: < 2.0.10-lp151.2.1
- (no CPE)range: < 0.7.6-lp151.5.1
- (no CPE)range: < 1.8.0-lp151.3.9.1
- (no CPE)range: < 1.6.0
- (no CPE)range: < 0.7.1-3.3.1
- (no CPE)range: < 0.8.4-3.3.1
- (no CPE)range: < 2.0.10-3.3.1
- (no CPE)range: < 0.7.6-3.6.1
- (no CPE)range: < 1.8.0-4.14.1
- (no CPE)range: < 0.7.1-3.3.1
- (no CPE)range: < 0.8.4-3.3.1
- (no CPE)range: < 0.7.1-lp151.2.3.1
Patches
Vulnerability mechanics
References
8- github.com/containers/libpod/commit/5c09c4d2947a759724f9d5aef6bac04317e03f7envdPatchWEB
- github.com/containers/libpod/compare/v1.5.1...v1.6.0nvdPatchWEB
- github.com/containers/libpod/issues/3829nvdExploitThird Party AdvisoryWEB
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party AdvisoryWEB
- github.com/advisories/GHSA-r34v-gqmw-qvgjghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2019-18466ghsaADVISORY
- access.redhat.com/errata/RHSA-2019:4269nvdWEB
- lists.opensuse.org/opensuse-security-announce/2020-03/msg00040.htmlnvd
News mentions
0No linked articles in our index yet.