Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-91299.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-91299
Upstream
Published
2026-06-26T17:16:34Z
Modified
2026-08-30T05:24:52Z
Summary
CVE-2026-55686 affecting package podman 5.6.1-9
Details

Podman is a tool for managing OCI containers and pods. From 3.0.0 until 5.7.1, running a malicious container image where the WORKDIR path contains a symlink can create a directory or modify ownership on the host filesystem. Modified ownership is less likely to happen as that requires help from an untrusted/malicious process that mutates the host filesystem tree during dereferencing of the WORKDIR path, to trigger a race condition. This vulnerability is fixed in 5.7.1.

References

Affected packages

Azure Linux:3 / podman

Package

Name
podman
Purl
pkg:rpm/azure-linux/podman

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
5.6.1-9

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-91299.json"