[ALSA-2026:69961] Important: podman security update
Type:
security
Severity:
important
Release date:
2026-09-23
Description:
The podman tool manages pods, container images, and containers. It is part of the libpod library, which is for applications that use container pods. Container pods is a concept in Kubernetes. Security Fix(es): * podman: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818) * podman: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860) * podman: Go: Denial of Service via XML decoding recursion depth issue (CVE-2026-56859) * podman: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858) * podman: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862) * podman: Quadlet install --replace non-truncating write retains removed host-access directives (CVE-2026-19730) * podman: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses (CVE-2026-39830) * podman: Go net/[http:](http:) Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853) * podman: moby/go-archive: Arbitrary file write via link following in tar extraction (CVE-2026-17106) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 podman-5.8.2-7.el9_8.aarch64.rpm 04f8d4ce624f33b4a55dfad65a4bcc03d3d898f648f2412f053b00e55d80cb86
aarch64 podman-tests-5.8.2-7.el9_8.aarch64.rpm 6ac2ad463885d9a68dbfac42dc6d7352aa8dbe27575980b6e6d5aacc92661b91
aarch64 podman-plugins-5.8.2-7.el9_8.aarch64.rpm 71303f4dd45ef5a4af72c83f3d59f1213d2616918b43b0b5acc487f41ca18df0
aarch64 podman-remote-5.8.2-7.el9_8.aarch64.rpm ceb8b730ae53709abdd0d443823f17294cd370723273ea0fa88ea63fb967beb0
noarch podman-docker-5.8.2-7.el9_8.noarch.rpm fd163f1ef56d10ba0e6833a4f1abf995c8ed30151e9041b68dd7a6cdf2338f63
ppc64le podman-plugins-5.8.2-7.el9_8.ppc64le.rpm 4495ace2d45145bd1719febb52f32e295fb3758b5f9e288c438a07e175a3972a
ppc64le podman-5.8.2-7.el9_8.ppc64le.rpm 5e17f068762b8c31073bd4a4a4d440a1c35e0710103ec3fd1770b746af77850f
ppc64le podman-tests-5.8.2-7.el9_8.ppc64le.rpm 6381f037457bba0fedd0f7782780d0f4b6b889ef61d527b9c61b8f8ffc72549c
ppc64le podman-remote-5.8.2-7.el9_8.ppc64le.rpm 81e3c81a2ad0069fb458f25133dc08351377e45541f552bda31a6526b55bf701
s390x podman-5.8.2-7.el9_8.s390x.rpm 19f28a683759cabfd4a05292a28ce995c5bd2ac67d39f89c9ce1546515c14817
s390x podman-tests-5.8.2-7.el9_8.s390x.rpm 3729cefa3756eca0c7fac9a43afc4e762413cfc5a32fa38366f67773d803476a
s390x podman-plugins-5.8.2-7.el9_8.s390x.rpm 3a9060dc519b71d25b39583328392994ed855a65c3d941de9e85543506a7bc95
s390x podman-remote-5.8.2-7.el9_8.s390x.rpm 467e46e033b1508f78ec2cc79b0078d3455f2efbaf6f3a3f6be521a13189496a
x86_64 podman-5.8.2-7.el9_8.x86_64.rpm 3867203180755ba431003581247aeaf59e21527dac4dfb45d1729a4c37cad444
x86_64 podman-plugins-5.8.2-7.el9_8.x86_64.rpm 46eb0fdc63f14386497eb4e6773de178af0c9f3e1c1887d2ef1dd4826cf21adf
x86_64 podman-remote-5.8.2-7.el9_8.x86_64.rpm 558674839eee2c6721c9d1adc1d076899f8872cdd1d09346f2c32a6de042ea4c
x86_64 podman-tests-5.8.2-7.el9_8.x86_64.rpm c1d6da9bf41ddca43ca71ab797c8f4b5327244b0a89ad28baa76c265f73012ee
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.