CVE-2020-1726
Summary
| CVE | CVE-2020-1726 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-02-11 20:15:00 UTC |
| Updated | 2023-02-12 23:40:00 UTC |
| Description | A flaw was discovered in Podman where it incorrectly allows containers when created to overwrite existing files in volumes, even if they are mounted as read-only. When a user runs a malicious container or a container based on a malicious image with an attached volume that is used for the first time, it is possible to trigger the flaw and overwrite files in the volume.This issue was introduced in version 1.6.0. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| 1801152 – (CVE-2020-1726) CVE-2020-1726 podman: incorrectly allows existing files in volumes to be overwritten by a container when it is created |
CONFIRM |
bugzilla.redhat.com |
Issue Tracking, Patch, Third Party Advisory |
| [security-announce] openSUSE-SU-2020:1559-1: moderate: Security update f |
SUSE |
lists.opensuse.org |
|
| Red Hat Customer Portal - Access to 24x7 support and knowledge |
MISC |
access.redhat.com |
|
| 1801152 – (CVE-2020-1726) CVE-2020-1726 podman: incorrectly allows existing files in volumes to be overwritten by a container when it is created |
MISC |
bugzilla.redhat.com |
|
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
|
| [security-announce] openSUSE-SU-2020:1552-1: moderate: Security update f |
SUSE |
lists.opensuse.org |
|
| Red Hat Customer Portal |
MISC |
access.redhat.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159667 Oracle Enterprise Linux Security Update for container-tools:ol8 (ELSA-2020-1650)
- 377377 Alibaba Cloud Linux Security Update for container-tools:rhel8 (ALINUX3-SA-2021:0013)
- 501895 Alpine Linux Security Update for podman
- 750618 OpenSUSE Security Update for conmon, fuse-overlayfs, libcontainers-common, podman (openSUSE-SU-2020:1559-1)
- 750623 OpenSUSE Security Update for conmon, fuse-overlayfs, libcontainers-common, podman (openSUSE-SU-2020:1552-1)
- 770014 Red Hat OpenShift Container Platform 4.3.5 Security Update (RHSA-2020:0680)
- 940531 AlmaLinux Security Update for container-tools:rhel8 (ALSA-2020:1650)
- 960829 Rocky Linux Security Update for container-tools:rhel8 (RLSA-2020:1650)