Container Network Stack Vulnerability in Podman by Red Hat
CVE-2025-8283

3.7LOW

What is CVE-2025-8283?

A vulnerability in the netavark package, utilized by Podman for container networking, may lead to unintended redirection to external servers. The issue arises from the removal of the dns.podman search domain, which allows the system to resolve container names using the host's resolv.conf. As a result, if the hostname of a running container collides with a name in the host's DNS search domains, connections may inadvertently be forwarded to unauthorized external servers, potentially exposing sensitive data or compromising system integrity.

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Johannes Kasberger for reporting this issue.
.
CVE-2025-8283 : Container Network Stack Vulnerability in Podman by Red Hat