Link Following The advisory has been revoked - it doesn't affect any version of package podman-fips  (opens in a new tab)


Threat Intelligence

EPSS
0.34% (26th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-CHAINGUARDLATEST-PODMANFIPS-14913395
  • published12 Jan 2026
  • disclosed29 Mar 2023

Introduced: 29 Mar 2023

CVE-2023-28642  (opens in a new tab)
CWE-59  (opens in a new tab)

Amendment

The Chainguard security team deemed this advisory irrelevant for Chainguard:latest.

NVD Description

Note: Versions mentioned in the description apply only to the upstream podman-fips package and not the podman-fips package as distributed by Chainguard.

runc is a CLI tool for spawning and running containers according to the OCI specification. It was found that AppArmor can be bypassed when /proc inside the container is symlinked with a specific mount configuration. This issue has been fixed in runc version 1.1.5, by prohibiting symlinked /proc. See PR #3785 for details. users are advised to upgrade. Users unable to upgrade should avoid using an untrusted container image.