These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
Buildah, a tool for building OCI images, has a vulnerability in versions 1.38.1 to 1.43.2 and 1.44.0. The issue lies in the TempDirForURL function, which does not securely confine Git repository subdirectories to the downloaded build context. This allows a malicious server supplying a Git repository or tar archive to include files outside the build context directory in the context or copy them into the bu [truncated]
A local rootful crun replay can create fixed device nodes and symlinks outside the rootfs before crun returns failure due to a default device setup issue in crun versions prior to 1.28. This issue arises from crun's default device setup opening the container rootfs `/dev` directory without `O_NOFOLLOW`, allowing for potential unintended device node creation outside the container rootfs. Defenders managing [truncated]
A low-privileged process can leave an upper-layer file with mode 4777 in fuse-overlayfs versions prior to 1.17, allowing unintended access. This issue is fixed in version 1.17. The vulnerability arises from the preservation of SUID and SGID mode bits in main.c during open(O_TRUNC) and truncate handling on a copied-up file. This could lead to unintended file access and manipulation. Defenders should assess [truncated]
CVE-2026-41163 is a high-severity bubblewrap issue affecting setuid installations. In vulnerable versions, a user can use ptrace to interfere with the unprivileged part of sandbox setup and steer privileged operations, including overlay mounts. The issue is fixed in bubblewrap 0.11.2.
CVE-2026-33414 is a command injection vulnerability in the HyperV machine backend of Podman, a tool for managing OCI containers and pods. The vulnerability exists in versions 4.8.0 through 5.8.1 and is caused by the insertion of a VM image path into a PowerShell double-quoted string without sanitization, allowing $() subexpression injection. This vulnerability allows an attacker to execute arbitrary Power [truncated]
Aardvark-dns, an authoritative DNS server for A/AAAA container records, is vulnerable to an infinite error loop at 100% CPU caused by a truncated TCP DNS query followed by a connection reset. This issue affects versions from 1.16.0 to 1.17.0 and is fixed in version 1.17.1. The vulnerability has a CVSS score of 6.2, indicating medium severity. Users of Aardvark-DNS should update to version 1.17.1 to preven [truncated]