rpm package
almalinux/podman-plugins
pkg:rpm/almalinux/podman-plugins
Vulnerabilities (123)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-17106 | Hig | — | < 6:5.8.2-7.el9_8 | 6:5.8.2-7.el9_8 | Aug 18, 2026 | The tar extraction routines in moby/go-archive (Unpack, UnpackLayer, Untar/UntarUncompressed, and the ApplyLayer helpers) do not confine filesystem operations to the destination directory. The extractor decides where each archive entry lands using lexical string checks and then p | |
| CVE-2026-56862 | Hig | 7.5 | < 4:4.9.4-37.module_el8.10.0+4269+94686149 | 4:4.9.4-37.module_el8.10.0+4269+94686149 | Aug 13, 2026 | Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indef | |
| CVE-2026-56860 | Med | 5.9 | < 4:4.9.4-37.module_el8.10.0+4269+94686149 | 4:4.9.4-37.module_el8.10.0+4269+94686149 | Aug 13, 2026 | Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-b | |
| CVE-2026-56859 | Hig | 7.5 | < 4:4.9.4-37.module_el8.10.0+4269+94686149 | 4:4.9.4-37.module_el8.10.0+4269+94686149 | Aug 13, 2026 | Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion. | |
| CVE-2026-56858 | Med | 6.1 | < 4:4.9.4-37.module_el8.10.0+4269+94686149 | 4:4.9.4-37.module_el8.10.0+4269+94686149 | Aug 13, 2026 | Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS. | |
| CVE-2026-56853 | Hig | 7.5 | < 4:4.9.4-37.module_el8.10.0+4269+94686149 | 4:4.9.4-37.module_el8.10.0+4269+94686149 | Aug 13, 2026 | When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this. | |
| CVE-2026-33818 | Hig | 7.5 | < 4:4.9.4-37.module_el8.10.0+4269+94686149 | 4:4.9.4-37.module_el8.10.0+4269+94686149 | Aug 13, 2026 | Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures. | |
| CVE-2026-19730 | Med | 4.2 | < 6:5.8.2-7.el9_8 | 6:5.8.2-7.el9_8 | Aug 13, 2026 | The 'podman quadlet install --replace' command opens the existing destination file with O_CREATE|O_WRONLY but omits O_TRUNC. When the initial reflink copy attempt fails (common on non-reflink-capable filesystems including many RHEL default XFS configurations), the fallback in Ref | |
| CVE-2026-39822 | Hig | 7.8 | < 6:5.8.2-5.el9_8 | 6:5.8.2-5.el9_8 | Jul 8, 2026 | On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open("symlink/")' will open "symlink" even when "symlink" is a symb | |
| CVE-2026-57231 | Hig | 7.5 | < 6:5.8.2-4.el9_8 | 6:5.8.2-4.el9_8 | Jun 26, 2026 | Podman is a tool for managing OCI containers and pods. From 1.8.1 until 5.8.4, a container image that contains a environment variable with just a key and no value can trick podman into passing that variable from the host into the container. This is made worse by the fact that usi | |
| CVE-2026-27136 | Med | 6.1 | < 6:5.8.2-4.el9_8 | 6:5.8.2-4.el9_8 | May 22, 2026 | Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering. | |
| CVE-2026-25681 | Med | 6.1 | < 6:5.8.2-4.el9_8 | 6:5.8.2-4.el9_8 | May 22, 2026 | Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering. | |
| CVE-2026-42508 | Cri | 9.1 | < 4:4.9.4-32.module_el8.10.0+4213+0493256b | 4:4.9.4-32.module_el8.10.0+4213+0493256b | May 22, 2026 | Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked. | |
| CVE-2026-39835 | Med | 5.3 | < 6:5.8.2-4.el9_8 | 6:5.8.2-4.el9_8 | May 22, 2026 | SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking when these callbacks are nil. | |
| CVE-2026-39832 | Cri | 9.1 | < 4:4.9.4-32.module_el8.10.0+4213+0493256b | 4:4.9.4-32.module_el8.10.0+4213+0493256b | May 22, 2026 | When adding a key to a remote agent constraint extensions such as [email protected] were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of the key on the remote host. The client now | |
| CVE-2026-39830 | Cri | 9.1 | < 4:4.9.4-32.module_el8.10.0+4213+0493256b | 4:4.9.4-32.module_el8.10.0+4213+0493256b | May 22, 2026 | A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked goroutine could not be released by calling Close(), resulting in a resource leak per connection. Unsolicited global responses are now | |
| CVE-2026-39829 | Hig | 7.5 | < 4:4.9.4-32.module_el8.10.0+4213+0493256b | 4:4.9.4-32.module_el8.10.0+4213+0493256b | May 22, 2026 | The RSA and DSA public key parsers did not enforce size limits on key parameters. A crafted public key with an excessively large modulus or DSA parameter could cause several minutes of CPU consumption during signature verification. This could be triggered by unauthenticated clien | |
| CVE-2026-42499 | Hig | 7.5 | < 4:4.9.4-37.module_el8.10.0+4269+94686149 | 4:4.9.4-37.module_el8.10.0+4269+94686149 | May 7, 2026 | Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322. | |
| CVE-2026-33811 | Hig | 7.5 | < 4:4.9.4-34.module_el8.10.0+4227+f1240cfc | 4:4.9.4-34.module_el8.10.0+4227+f1240cfc | May 7, 2026 | When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash. | |
| CVE-2026-32283 | Hig | 7.5 | < 6:5.8.2-3.el9_8 | 6:5.8.2-3.el9_8 | Apr 8, 2026 | If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3. |
- affected < 6:5.8.2-7.el9_8fixed 6:5.8.2-7.el9_8
The tar extraction routines in moby/go-archive (Unpack, UnpackLayer, Untar/UntarUncompressed, and the ApplyLayer helpers) do not confine filesystem operations to the destination directory. The extractor decides where each archive entry lands using lexical string checks and then p
- affected < 4:4.9.4-37.module_el8.10.0+4269+94686149fixed 4:4.9.4-37.module_el8.10.0+4269+94686149
Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indef
- affected < 4:4.9.4-37.module_el8.10.0+4269+94686149fixed 4:4.9.4-37.module_el8.10.0+4269+94686149
Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-b
- affected < 4:4.9.4-37.module_el8.10.0+4269+94686149fixed 4:4.9.4-37.module_el8.10.0+4269+94686149
Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion.
- affected < 4:4.9.4-37.module_el8.10.0+4269+94686149fixed 4:4.9.4-37.module_el8.10.0+4269+94686149
Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS.
- affected < 4:4.9.4-37.module_el8.10.0+4269+94686149fixed 4:4.9.4-37.module_el8.10.0+4269+94686149
When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this.
- affected < 4:4.9.4-37.module_el8.10.0+4269+94686149fixed 4:4.9.4-37.module_el8.10.0+4269+94686149
Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures.
- affected < 6:5.8.2-7.el9_8fixed 6:5.8.2-7.el9_8
The 'podman quadlet install --replace' command opens the existing destination file with O_CREATE|O_WRONLY but omits O_TRUNC. When the initial reflink copy attempt fails (common on non-reflink-capable filesystems including many RHEL default XFS configurations), the fallback in Ref
- affected < 6:5.8.2-5.el9_8fixed 6:5.8.2-5.el9_8
On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open("symlink/")' will open "symlink" even when "symlink" is a symb
- affected < 6:5.8.2-4.el9_8fixed 6:5.8.2-4.el9_8
Podman is a tool for managing OCI containers and pods. From 1.8.1 until 5.8.4, a container image that contains a environment variable with just a key and no value can trick podman into passing that variable from the host into the container. This is made worse by the fact that usi
- affected < 6:5.8.2-4.el9_8fixed 6:5.8.2-4.el9_8
Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.
- affected < 6:5.8.2-4.el9_8fixed 6:5.8.2-4.el9_8
Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.
- affected < 4:4.9.4-32.module_el8.10.0+4213+0493256bfixed 4:4.9.4-32.module_el8.10.0+4213+0493256b
Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked.
- affected < 6:5.8.2-4.el9_8fixed 6:5.8.2-4.el9_8
SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking when these callbacks are nil.
- affected < 4:4.9.4-32.module_el8.10.0+4213+0493256bfixed 4:4.9.4-32.module_el8.10.0+4213+0493256b
When adding a key to a remote agent constraint extensions such as [email protected] were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of the key on the remote host. The client now
- affected < 4:4.9.4-32.module_el8.10.0+4213+0493256bfixed 4:4.9.4-32.module_el8.10.0+4213+0493256b
A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked goroutine could not be released by calling Close(), resulting in a resource leak per connection. Unsolicited global responses are now
- affected < 4:4.9.4-32.module_el8.10.0+4213+0493256bfixed 4:4.9.4-32.module_el8.10.0+4213+0493256b
The RSA and DSA public key parsers did not enforce size limits on key parameters. A crafted public key with an excessively large modulus or DSA parameter could cause several minutes of CPU consumption during signature verification. This could be triggered by unauthenticated clien
- affected < 4:4.9.4-37.module_el8.10.0+4269+94686149fixed 4:4.9.4-37.module_el8.10.0+4269+94686149
Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.
- affected < 4:4.9.4-34.module_el8.10.0+4227+f1240cfcfixed 4:4.9.4-34.module_el8.10.0+4227+f1240cfc
When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash.
- affected < 6:5.8.2-3.el9_8fixed 6:5.8.2-3.el9_8
If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.
Page 1 of 7