Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-18722

Опубликовано: 26 июн. 2026
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2026-18722: podman security update (IMPORTANT)

[5.8.2-3.0.1]

  • Rework CNI/Netavark detection logic [JIRA: EVG-3769]
  • Rebuild on new golang to support experimental GODEBUG fipsnoenforceems
  • Drop nmap-ncat requirement and skip ignore-socket test case [Orabug: 34117404]

[6:5.8.2-3]

  • Rebuild for CVE-2026-32283
  • Resolves: RHEL-167685

[6:5.8.2-2]

  • Rebuild for CVE-2026-25679
  • Resolves: RHEL-158781

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

podman

5.8.2-3.0.1.el9_8

podman-docker

5.8.2-3.0.1.el9_8

podman-plugins

5.8.2-3.0.1.el9_8

podman-remote

5.8.2-3.0.1.el9_8

podman-tests

5.8.2-3.0.1.el9_8

Oracle Linux x86_64

podman

5.8.2-3.0.1.el9_8

podman-docker

5.8.2-3.0.1.el9_8

podman-plugins

5.8.2-3.0.1.el9_8

podman-remote

5.8.2-3.0.1.el9_8

podman-tests

5.8.2-3.0.1.el9_8

Связанные CVE

Связанные уязвимости

CVSS3: 8.1
ubuntu
11 месяцев назад

There's a vulnerability in podman where an attacker may use the kube play command to overwrite host files when the kube file container a Secrete or a ConfigMap volume mount and such volume contains a symbolic link to a host file path. In a successful attack, the attacker can only control the target file to be overwritten but not the content to be written into the file. Binary-Affected: podman Upstream-version-introduced: v4.0.0 Upstream-version-fixed: v5.6.1

CVSS3: 8.1
redhat
11 месяцев назад

There's a vulnerability in podman where an attacker may use the kube play command to overwrite host files when the kube file container a Secrete or a ConfigMap volume mount and such volume contains a symbolic link to a host file path. In a successful attack, the attacker can only control the target file to be overwritten but not the content to be written into the file. Binary-Affected: podman Upstream-version-introduced: v4.0.0 Upstream-version-fixed: v5.6.1

CVSS3: 8.1
nvd
11 месяцев назад

There's a vulnerability in podman where an attacker may use the kube play command to overwrite host files when the kube file container a Secrete or a ConfigMap volume mount and such volume contains a symbolic link to a host file path. In a successful attack, the attacker can only control the target file to be overwritten but not the content to be written into the file. Binary-Affected: podman Upstream-version-introduced: v4.0.0 Upstream-version-fixed: v5.6.1

msrc
11 месяцев назад

Podman: podman kube play command may overwrite host files

CVSS3: 8.1
debian
11 месяцев назад

There's a vulnerability in podman where an attacker may use the kube p ...