{"id":"AZL-91299","summary":"CVE-2026-55686 affecting package podman 5.6.1-10","details":"Podman is a tool for managing OCI containers and pods. From 3.0.0 until 5.7.1, running a malicious container image where the WORKDIR path contains a symlink can create a directory or modify ownership on the host filesystem. Modified ownership is less likely to happen as that requires help from an untrusted/malicious process that mutates the host filesystem tree during dereferencing of the WORKDIR path, to trigger a race condition. This vulnerability is fixed in 5.7.1.","modified":"2026-09-10T05:26:53Z","published":"2026-06-26T17:16:34Z","upstream":["CVE-2026-55686"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55686"}],"affected":[{"package":{"name":"podman","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/podman"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"5.6.1-10"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-91299.json"}}],"schema_version":"1.9.0"}