[ALSA-2026:70201] Important: podman security update
Type:
security
Severity:
important
Release date:
2026-09-23
Description:
The podman tool manages pods, container images, and containers. It is part of the libpod library, which is for applications that use container pods. Container pods is a concept in Kubernetes. Security Fix(es): * podman: Go crypto/x509: Certificate validation bypass due to incorrect DNS constraint application (CVE-2026-33810) * podman: Go net/[http:](http:) Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853) * podman: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818) * podman: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860) * podman: Go: Denial of Service via XML decoding recursion depth issue (CVE-2026-56859) * podman: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858) * podman: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862) * podman: golang.org/x/text: Denial of Service via invalid UTF-8 input (CVE-2026-56852) * podman: net/mail: Denial of Service via pathological email address parsing (CVE-2026-42499) * podman: Quadlet install --replace non-truncating write retains removed host-access directives (CVE-2026-19730) * podman: moby/go-archive: Arbitrary file write via link following in tar extraction (CVE-2026-17106) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 podman-5.8.2-9.el10_2.alma.1.aarch64.rpm 01121f16d5ad2f5da3608eb0dd4825ca927e77d0dca5130e0b1347d9e648628c
aarch64 podman-remote-5.8.2-9.el10_2.alma.1.aarch64.rpm af70314866593ac9649f0f793195805165ebc47522817d2cc27cfbea9e75ddad
aarch64 podman-tests-5.8.2-9.el10_2.alma.1.aarch64.rpm b2468792044e1eb80fed2eacd44242f80d7e547c364a2047d9c7631144917347
noarch podman-docker-5.8.2-9.el10_2.alma.1.noarch.rpm f46c4a2f1c8d19490236bd31637b67ed406bf45d03eeaf0ed986334693a23e6a
ppc64le podman-5.8.2-9.el10_2.alma.1.ppc64le.rpm 061f997db43456a60bb396b2d63e89689980454d3a5b173810d56c7a5f57034f
ppc64le podman-remote-5.8.2-9.el10_2.alma.1.ppc64le.rpm 40f5a45ad8bb7e68540651b4c09782a39c4e82c5c23679c8a1ecdfecf0a85aae
ppc64le podman-tests-5.8.2-9.el10_2.alma.1.ppc64le.rpm 44fe49f9a26c71683705beb6cd9c44071b8d22ff028f27af4160fcc6fab6a6b6
s390x podman-remote-5.8.2-9.el10_2.alma.1.s390x.rpm 6c3f885f9c23a7e0d3e26e06a668557dc60b4a0f2dada209744ec8cb9325ac52
s390x podman-5.8.2-9.el10_2.alma.1.s390x.rpm acba4292e47b07b3c4564b756937af49d0dcf4d470a460df00f462be276c93a6
s390x podman-tests-5.8.2-9.el10_2.alma.1.s390x.rpm ffe0c35f6f65b61332f23c392c29dfe454a836c2c94d96639388eb531d2c4c54
x86_64 podman-5.8.2-9.el10_2.alma.1.x86_64.rpm 2ed70839a899a405681e59dc9b68ea1b6f7a9a2331913edaad0f1890fbc185b1
x86_64 podman-remote-5.8.2-9.el10_2.alma.1.x86_64.rpm 9a4267f0ef0ed21e13d32d96732b90f2e3e3518692218d0541f5dd94802b7601
x86_64 podman-tests-5.8.2-9.el10_2.alma.1.x86_64.rpm e310b1deccad0f10d22936986e153b5b1635c1bf47e01d5cc4f43182e7d799b3
x86_64_v2 podman-remote-5.8.2-9.el10_2.alma.1.x86_64_v2.rpm 589192de9c1defdcd0f8326b8c7a5ea9a07f92d5e8ef3678e62340b38a490e6b
x86_64_v2 podman-5.8.2-9.el10_2.alma.1.x86_64_v2.rpm 6bc18dc079aed31dda3260526b24aa74a59a1fe6cc16494d601d072136f4cf50
x86_64_v2 podman-tests-5.8.2-9.el10_2.alma.1.x86_64_v2.rpm e86e752615ff2370e2d2d811537c2c764e01f4696ad3422938308eaf9b03e3af
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.