Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2025-10549

Опубликовано: 08 июл. 2025
Источник: oracle-oval
Платформа: Oracle Linux 10

Описание

ELSA-2025-10549: podman security update (IMPORTANT)

[6:5.4.0-12.0.1]

  • Add devices on container startup, not on creation
  • overlay: Put should ignore ENINVAL for Unmount [Orabug: 36234694]
  • Drop nmap-ncat requirement and skip ignore-socket test case [Orabug: 34117404]

[6:5.4.0-12]

Обновленные пакеты

Oracle Linux 10

Oracle Linux aarch64

podman

5.4.0-12.0.1.el10_0

podman-docker

5.4.0-12.0.1.el10_0

podman-remote

5.4.0-12.0.1.el10_0

podman-tests

5.4.0-12.0.1.el10_0

Oracle Linux x86_64

podman

5.4.0-12.0.1.el10_0

podman-docker

5.4.0-12.0.1.el10_0

podman-remote

5.4.0-12.0.1.el10_0

podman-tests

5.4.0-12.0.1.el10_0

Связанные CVE

Связанные уязвимости

CVSS3: 8.3
ubuntu
28 дней назад

A flaw was found in Podman. The podman machine init command fails to verify the TLS certificate when downloading the VM images from an OCI registry. This issue results in a Man In The Middle attack.

CVSS3: 8.3
redhat
29 дней назад

A flaw was found in Podman. The podman machine init command fails to verify the TLS certificate when downloading the VM images from an OCI registry. This issue results in a Man In The Middle attack.

CVSS3: 8.3
nvd
28 дней назад

A flaw was found in Podman. The podman machine init command fails to verify the TLS certificate when downloading the VM images from an OCI registry. This issue results in a Man In The Middle attack.

CVSS3: 8.3
debian
28 дней назад

A flaw was found in Podman. The podman machine init command fails to v ...

CVSS3: 8.3
github
27 дней назад

Podman Improper Certificate Validation; machine missing TLS verification