A Time-of-check Time-of-use (TOCTOU) flaw was found in podman.

Link.


When researching Red Hat’s container runtime engine Podman, a TOCTOU vulnerability caused by incorrect parsing of the container path was discovered by us. It was acknowledged by Podman, and a medium-high-risk CVE-2023-0778 (with a CVSS score of 6.8) was obtained. This issue may allow a malicious user to replace a normal file in a volume with a symlink while exporting the volume, allowing for access to arbitrary files on the host file system.