A vulnerability was found in the netavark package, a network stack for containers used with Podman. Due to dns.podman search domain being removed, netavark may return external servers if a valid A/AA…
低危 CVSS 3.7
摘要
A vulnerability was found in the netavark package, a network stack for containers used with Podman. Due to dns.podman search domain being removed, netavark may return external servers if a valid A/AAAA record is sent as a response. When creating a container with a given name, this name will be used as the hostname for the container itself, as the podman's search domain is not added anymore the container is using the host's resolv.conf, and the DNS resolver will try to look into the search domai…
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
受影响产品
- :
数据来源
- NVD DATABASE
原始链接
- https://access.redhat.com/security/cve/CVE-2025-8283 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2383941 Issue Tracking
- https://github.com/advisories/GHSA-rpcf-rmh6-42xr
- https://github.com/containers/netavark/releases/tag/v1.15.1
- https://github.com/containers/podman/issues/2619
时间线
- nvd_ingest NVD