FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

podman -- vulnerabilities

Affected packages
podman < 5.8.7

Details

VuXML ID 050e54b4-b81e-11f1-b540-589cfc10a551
Discovery 2026-09-16
Entry 2026-09-24

The Podman developers report:

This release addresses (CVE-2025-11395), where importing images containing crafted layer tarballs with the podman load command, or importing volumes containing crafted symlinks with podman volume import, allows overwriting files on the host.

This release also addresses CVE-2026-79699 and CVE-2026-79705, though we do not believe these CVEs are exploitable through the Podman command line.

References

CVE Name CVE-2025-11395
CVE Name CVE-2026-79699
CVE Name CVE-2026-79705
URL https://github.com/podman-container-tools/podman/releases/tag/v5.8.7