Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Related to CVE-2025-11395 embargo family. PSIRTSUPT-21911. Confirmed vector: macOS Podman remote client performing podman cp against a malicious podman system service server serving crafted tar with symlinks. Other vectors possible but unconfirmed. Patch available, not yet released.
Comment 1Fedora Admin user for bugzilla script actions
2026-09-23 21:47:19 UTC
This package has changed maintainer in Fedora. Reassigning to the new maintainer of this component.