github.com/containers/libpod is vulnerable to unauthorised file overwritten. The library fails to check if the volume is empty before copying even if the containers are mounted as read-only, allowing the existing files in the volumes to be overwritten.
lists.opensuse.org/opensuse-security-announce/2020-09/msg00097.html
lists.opensuse.org/opensuse-security-announce/2020-09/msg00103.html
access.redhat.com/errata/RHSA-2020:0680
access.redhat.com/errata/RHSA-2020:1650
access.redhat.com/security/cve/CVE-2020-1726
bugzilla.redhat.com/show_bug.cgi?id=1801152
bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1726
github.com/containers/libpod/pull/5168