A vulnerability was found in the netavark package, a network stack for containers used with Podman. Due to dns.podman search domain being removed, netavark may return external servers if a valid A/AA…
Low CVSS 3.7
Summary
A vulnerability was found in the netavark package, a network stack for containers used with Podman. Due to dns.podman search domain being removed, netavark may return external servers if a valid A/AAAA record is sent as a response. When creating a container with a given name, this name will be used as the hostname for the container itself, as the podman's search domain is not added anymore the container is using the host's resolv.conf, and the DNS resolver will try to look into the search domai…
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://access.redhat.com/security/cve/CVE-2025-8283 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2383941 Issue Tracking
- https://github.com/advisories/GHSA-rpcf-rmh6-42xr
- https://github.com/containers/netavark/releases/tag/v1.15.1
- https://github.com/containers/podman/issues/2619
Timeline
- nvd_ingest NVD