Your message dated Tue, 25 Aug 2026 11:34:46 +0000
with message-id <[email protected]>
and subject line Bug#1145198: fixed in podman 5.8.6+ds1-1
has caused the Debian Bug report #1145198,
regarding podman: CVE-2026-19730
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1145198: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1145198
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: podman
Version: 5.8.4+ds1-2
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi,
The following vulnerability was published for podman.
CVE-2026-19730[0]:
| The 'podman quadlet install --replace' command opens the existing
| destination file with O_CREATE|O_WRONLY but omits O_TRUNC. When the
| initial reflink copy attempt fails (common on non-reflink-capable
| filesystems including many RHEL default XFS configurations), the
| fallback in ReflinkOrCopy uses io.Copy which performs a non-
| truncating write. If the original Quadlet is larger than the new
| Quadlet, the file is not truncated and content from the original is
| preserved. The command completes with no warning. There is no risk
| of information leakage as the user already had access to the Quadlet
| in order to replace it, and in most cases, this would only lead to
| invalid Quadlet files. However, security-related options from the
| end of the old Quadlet could be included in the new Quadlet, and if
| the truncation resulted in a valid Quadlet file, this could result
| in undesirable behavior. For example, running podman quadlet install
| --replace to remove a single line from the end of a Quadlet -
| including security-sensitive content, like AddCapability - will
| fail, and the option will continue to be used. Further, with Volume
| Quadlets, this can include additional mounts which can cause content
| to be unintentionally exposed into containers. If, later, the image
| is updated then compromised content might be leaked to an attacker.
| The vulnerable code paths are in pkg/domain/infra/abi/quadlet.go
| (lines 338-360, O_CREATE|O_WRONLY without O_TRUNC) and
| vendor/go.podman.io/storage/pkg/fileutils/reflink_linux.go (lines
| 12-19, non-truncating io.Copy fallback).
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-19730
https://www.cve.org/CVERecord?id=CVE-2026-19730
[1]
https://github.com/podman-container-tools/podman/security/advisories/GHSA-fx76-2j3w-2mx6
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: podman
Source-Version: 5.8.6+ds1-1
Done: Reinhard Tartler <[email protected]>
We believe that the bug you reported is fixed in the latest version of
podman, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Reinhard Tartler <[email protected]> (supplier of updated podman package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Tue, 25 Aug 2026 07:20:46 -0400
Source: podman
Architecture: source
Version: 5.8.6+ds1-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Go Packaging Team
<[email protected]>
Changed-By: Reinhard Tartler <[email protected]>
Closes: 1141972 1145198
Changes:
podman (5.8.6+ds1-1) unstable; urgency=medium
.
* Team Upload
* New Upstream Version, Fixes: CVE-2026-19730, Closes: #1145198
* Disable external compose provider warning by default (Closes: #1141972)
Checksums-Sha1:
2ba00e089c9d56ebaa1cbc7bf30bee2f832410f6 5100 podman_5.8.6+ds1-1.dsc
f40ebd0e6a9a56c82172bd997780fc362a11933e 3003884 podman_5.8.6+ds1.orig.tar.xz
cb5f4f851063392bc9c3e0865c0dc139b5eb9224 33252 podman_5.8.6+ds1-1.debian.tar.xz
25bca21be6fa8ffbc7841b6c8839b2cf430eaec4 5814348 podman_5.8.6+ds1-1.git.tar.xz
7ebd991f01a541254c9d7143bbcf3b872fe9a264 17672
podman_5.8.6+ds1-1_source.buildinfo
Checksums-Sha256:
adf2ad7dad31c27d25ee40492d3614462eb9b9f7a9a6cd346b4ce655ab0a63be 5100
podman_5.8.6+ds1-1.dsc
1581ba7c47e38b6856008a665d5fc76375b7e4504d116f7bee2024ede25c5a53 3003884
podman_5.8.6+ds1.orig.tar.xz
c60e940f9da9c42aac496389eb638f09346082712e5583f09323acd897b2a87d 33252
podman_5.8.6+ds1-1.debian.tar.xz
be214c86256ddfa2c6e952ffde0e32acdf1280a8637172c3e952146c111821aa 5814348
podman_5.8.6+ds1-1.git.tar.xz
be5024fc61dbdfeb7485d171a44dd424b4d90c5a450feedf39d087fe92883aef 17672
podman_5.8.6+ds1-1_source.buildinfo
Files:
ab12468672d711f6ebd4857bca8bb498 5100 admin optional podman_5.8.6+ds1-1.dsc
291e6a33a14cb72bfcc09479d355b00c 3003884 admin optional
podman_5.8.6+ds1.orig.tar.xz
d7c266f6f78f3a32a90496b8d846d117 33252 admin optional
podman_5.8.6+ds1-1.debian.tar.xz
7585217c228fee031c399199149711b3 5814348 admin None
podman_5.8.6+ds1-1.git.tar.xz
b5e85bd0c64e05498b0c62c2409f5b3d 17672 admin optional
podman_5.8.6+ds1-1_source.buildinfo
Git-Tag-Info: tag=cff45e5831504b215385ab6262a8d400dd9c82c9
fp=30de7d1763ab9452c7e0825049a76977942826cb
Git-Tag-Tagger: Reinhard Tartler <[email protected]>
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEN02M5NuW6cvUwJcqYG0ITkaDwHkFAmqNewMACgkQYG0ITkaD
wHnHahAAhuHANXBaqLgZFyzRKC8OMfp3MAezA21uExPl2EPV0NsnbPN1po7fFfn1
9VnRQG/Lbg8/dZM8OfxbzDtMQdQoB8CHLbez2+6g6fZf/Rv/Z0cLE8h6aXZgr7zk
8mDAfAQ0feJmhjG+scgk2kVBCRJS0wog/APfrzEw/TE0MUQuDPX+rJfkIkCiV+vG
wkLxEf7eItkBc3T0e6MSw644IGoYNP8FPComaqFlbQIqzEjrRLaxo1+jUfAtsQfJ
wzTcyPlMxBhnkTu+cea/1fM2LOPx5Gn8iVH6weslnisZ/hrVm5TlN7Q5qWIN3lqk
l2O6GTI8RDqaHmflUGFQ66Hy5pM1010SqJXbjyBTLMGTcUUEi2bmJ8Q+rhTJBuYQ
TbYMBT2FgPDe5ttZzTSsUhAwDBcLJnno5Ojv4C9U1MxDDcDccgzqpKWALBGXxrf4
Qd5XF74fCOrFp53NZa4iO211n/DTAKuHZzmSuKT7XQgGr9jXEjay+kd2Y88NjfDP
tKS92KvYnBtyB2fkS+/IvKOmy2AS3HWQvZhKvEfIJN3dehX42GS9w9NEH9dCeTcm
Qzav3IyG87EXyvaBDrRD/Tii9oBuRtgVMA5gbntlesQ+dPn46Kf8keNbgMwuep1o
RmHCuMMTfvGaR5Wnr/xMyQ/5VHPIapOQ39y7ZbAKcFhZ/JO15ao=
=ohSZ
-----END PGP SIGNATURE-----
pgp0ZynLSERUe.pgp
Description: PGP signature
--- End Message ---
_______________________________________________
Pkg-go-maintainers mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-go-maintainers