File Handling Flaw in Podman Affects User-Defined Quadlets by Red Hat
CVE-2026-19730

4.2MEDIUM

What is CVE-2026-19730?

A flaw in Podman 5.8.x occurs during the use of the 'podman quadlet install --replace' command, which does not truncate the existing file correctly. When the original Quadlet is larger than the new replacement Quadlet, remnants from the original file may persist. This can lead to the introduction of outdated security configurations within the new Quadlet, causing potential security risks if sensitive settings continue to be applied. While there is no direct information leakage, invalid configurations could result in unintended behavior, including exposure of insecure mounts when dealing with Volume Quadlets. It's crucial for users to be aware of this issue when managing their container configurations to avoid serious security implications.

References

CVSS V3.1

Score:
4.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Christopher Lusk (North Echo Security Research) and Paul Holzinger (Podman) for reporting this issue.
.