Medium severity5.3NVD Advisory· Published Jun 26, 2026· Updated Jun 26, 2026
CVE-2026-55686
CVE-2026-55686
Description
Podman is a tool for managing OCI containers and pods. From 3.0.0 until 5.7.1, running a malicious container image where the WORKDIR path contains a symlink can create a directory or modify ownership on the host filesystem. Modified ownership is less likely to happen as that requires help from an untrusted/malicious process that mutates the host filesystem tree during dereferencing of the WORKDIR path, to trigger a race condition. This vulnerability is fixed in 5.7.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/containers/podman/v5Go | < 5.7.1 | 5.7.1 |
github.com/containers/podman/v4Go | <= 4.9.5 | — |
github.com/containers/podman/v3Go | <= 3.4.7 | — |
Affected products
3- osv-coordsRange: < 0.0.20260723T184607-160000.1.1
Patches
Vulnerability mechanics
References
4- github.com/podman-container-tools/podman/commit/d18e44e9abb3bf5b7294aa70806e1368fdddfdd0nvdPatchWEB
- github.com/podman-container-tools/podman/security/advisories/GHSA-q6r4-3wmg-fwcqnvdExploitPatchVendor AdvisoryWEB
- github.com/advisories/GHSA-q6r4-3wmg-fwcqghsaADVISORY
- github.com/podman-container-tools/podman/commit/7ce2e00ab140c11a68301f0b161f51984131a858ghsaWEB
News mentions
0No linked articles in our index yet.