File Handling Flaw in Podman Affects User-Defined Quadlets by Red Hat
CVE-2026-19730
What is CVE-2026-19730?
A flaw in Podman 5.8.x occurs during the use of the 'podman quadlet install --replace' command, which does not truncate the existing file correctly. When the original Quadlet is larger than the new replacement Quadlet, remnants from the original file may persist. This can lead to the introduction of outdated security configurations within the new Quadlet, causing potential security risks if sensitive settings continue to be applied. While there is no direct information leakage, invalid configurations could result in unintended behavior, including exposure of insecure mounts when dealing with Volume Quadlets. It's crucial for users to be aware of this issue when managing their container configurations to avoid serious security implications.
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved