CVE-2023-0778

MEDIUM6.8EPSS 0.16%

Time-of-check time-of-use race condition in github.com/containers/podman/v4

Published: 3/27/2023Modified: 4/28/2026

Description

A Time-of-check Time-of-use (TOCTOU) flaw was found in podman. This issue may allow a malicious user to replace a normal file in a volume with a symlink while exporting the volume, allowing for access to arbitrary files on the host file system.

Affected packages (3)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM6.8CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N

References (10)