Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
To mitigate this issue, users should ensure that `podman cp` operations are only performed against trusted Podman system service servers. Copying content from untrusted sources may expose the client to directory traversal vulnerabilities.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 15 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 15 Sep 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in the buildah/copier Go package. When used outside of Buildah by a non-root caller, a crafted tar archive containing malicious symlinks can escape the target extraction directory and create files outside the intended destination. Buildah itself uses chroot hardening and is not affected. | |
| Title | Podman: buildah: buildah/copier: directory escape via crafted tar symlinks when used outside buildah by non-root callers | |
| First Time appeared |
Redhat
Redhat ansible Automation Platform Redhat container Native Virtualization Redhat enterprise Linux Redhat hummingbird Redhat openshift Redhat openshift Devspaces Redhat quay |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:/a:redhat:ansible_automation_platform:2 cpe:/a:redhat:container_native_virtualization:4 cpe:/a:redhat:hummingbird:1 cpe:/a:redhat:openshift:4 cpe:/a:redhat:openshift_devspaces:3 cpe:/a:redhat:quay:3 cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat ansible Automation Platform Redhat container Native Virtualization Redhat enterprise Linux Redhat hummingbird Redhat openshift Redhat openshift Devspaces Redhat quay |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-09-15T17:58:45.967Z
Reserved: 2026-08-25T12:47:21.722Z
Link: CVE-2026-79705
Updated: 2026-09-15T17:28:13.717Z
Status : Received
Published: 2026-09-15T17:17:27.313
Modified: 2026-09-15T18:19:21.677
Link: CVE-2026-79705
No data.
OpenCVE Enrichment
No data.