Source: podman Version: 5.8.4+ds1-2 Severity: important Tags: security upstream X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerability was published for podman. CVE-2026-19730[0]: | The 'podman quadlet install --replace' command opens the existing | destination file with O_CREATE|O_WRONLY but omits O_TRUNC. When the | initial reflink copy attempt fails (common on non-reflink-capable | filesystems including many RHEL default XFS configurations), the | fallback in ReflinkOrCopy uses io.Copy which performs a non- | truncating write. If the original Quadlet is larger than the new | Quadlet, the file is not truncated and content from the original is | preserved. The command completes with no warning. There is no risk | of information leakage as the user already had access to the Quadlet | in order to replace it, and in most cases, this would only lead to | invalid Quadlet files. However, security-related options from the | end of the old Quadlet could be included in the new Quadlet, and if | the truncation resulted in a valid Quadlet file, this could result | in undesirable behavior. For example, running podman quadlet install | --replace to remove a single line from the end of a Quadlet - | including security-sensitive content, like AddCapability - will | fail, and the option will continue to be used. Further, with Volume | Quadlets, this can include additional mounts which can cause content | to be unintentionally exposed into containers. If, later, the image | is updated then compromised content might be leaked to an attacker. | The vulnerable code paths are in pkg/domain/infra/abi/quadlet.go | (lines 338-360, O_CREATE|O_WRONLY without O_TRUNC) and | vendor/go.podman.io/storage/pkg/fileutils/reflink_linux.go (lines | 12-19, non-truncating io.Copy fallback). If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-19730 https://www.cve.org/CVERecord?id=CVE-2026-19730 [1] https://github.com/podman-container-tools/podman/security/advisories/GHSA-fx76-2j3w-2mx6 Please adjust the affected versions in the BTS as needed. Regards, Salvatore

