podman-5.8.2-4.el9_8

エラータID: AXSA:2026-1491:07

Release date: 
Friday, August 7, 2026 - 20:01
Subject: 
podman-5.8.2-4.el9_8
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
High
Description: 

The podman tool manages pods, container images, and containers. It is part of the libpod library, which is for applications that use container pods. Container pods is a concept in Kubernetes.

Security Fix(es):

* golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate (CVE-2026-39835)
* golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters (CVE-2026-39829)
* golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions (CVE-2026-39832)
* golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey (CVE-2026-42508)
* golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass (CVE-2026-27136)
* golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting (CVE-2026-25681)
* podman: Podman: Information disclosure via malicious container image environment variables (CVE-2026-57231)

Bug Fix(es) and Enhancement(s):

* podman does not clean up all files and leaves orphaned files consuming disk space [rhel-9.8.z] (JIRA:RHEL-173988)
* [FJ9.8 Bug]: [REG]The "podman-remote save" command fails for rootless users. [rhel-9.8.z] (JIRA:RHEL-192439)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-25681
Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.
CVE-2026-27136
Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.
CVE-2026-39829
The RSA and DSA public key parsers did not enforce size limits on key parameters. A crafted public key with an excessively large modulus or DSA parameter could cause several minutes of CPU consumption during signature verification. This could be triggered by unauthenticated clients during public key authentication. RSA moduli are now limited to 8192 bits, and DSA parameters are validated per FIPS 186-2.
CVE-2026-39832
When adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh.com were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of the key on the remote host. The client now serializes all constraint extensions. Additionally, the in-memory keyring returned by NewKeyring() now rejects keys with unsupported constraint extensions instead of silently ignoring them.
CVE-2026-39835
SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking when these callbacks are nil.
CVE-2026-42508
Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked.
CVE-2026-57231
Podman is a tool for managing OCI containers and pods. From 1.8.1 until 5.8.4, a container image that contains a environment variable with just a key and no value can trick podman into passing that variable from the host into the container. This is made worse by the fact that using an asterisk (*) will cause podman to pass all host variables into the container. So essentially a malicious image can exfiltrate all podman environment variables that are set in the session from where the container is launched. This vulnerability is fixed in 5.8.4 and 6.0.0.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. podman-5.8.2-4.el9_8.src.rpm
    MD5: c2fa3c2356f4d3dc0862e3f8643f102a
    SHA-256: ba226a7f01214956c2e65b7abfc0262d230f136336d9aea43700c158d835defa
    Size: 21.77 MB

Asianux Server 9 for x86_64
  1. podman-5.8.2-4.el9_8.x86_64.rpm
    MD5: 9e7e866645fc7ae147bfad726dfd3f62
    SHA-256: df1cfc6ee395a84c6b3f15ce09f5fe70edef929eb28d1f195db904ffd4e4f4fd
    Size: 16.48 MB
  2. podman-docker-5.8.2-4.el9_8.noarch.rpm
    MD5: 8282555b788d68ff84fe1dae0682e8c2
    SHA-256: 61ec652913639a52c12c0c716b782a83c90ab8ded692d8b93889bb1fbc7fe5a1
    Size: 106.39 kB
  3. podman-plugins-5.8.2-4.el9_8.x86_64.rpm
    MD5: 45ccffdd03bce2cd3e4396b8c3e9696b
    SHA-256: a890ba58cd19ecaeb25ff8f931120f25b8803f1a98b0a05b5e9c22a7572d63b2
    Size: 1.49 MB
  4. podman-remote-5.8.2-4.el9_8.x86_64.rpm
    MD5: 2c5f15718bc0e1cbdd37b32099843fbd
    SHA-256: 4899f9195c8d8d6ceb73b9dbe3b3d0928c24f88c101d534cec5afcdebb44d257
    Size: 10.13 MB
  5. podman-tests-5.8.2-4.el9_8.x86_64.rpm
    MD5: e76c8a316a6dfe040f1ffc22ab8c7778
    SHA-256: 8abc99e1ce1670cd4f8201c5eeac1999378ae29b59b9f00aa782a43a794332ba
    Size: 11.73 MB