#1145198 podman: CVE-2026-19730

Package:
src:podman
Source:
src:podman
Submitter:
Salvatore Bonaccorso
Date:
2026-08-23 19:13:02 UTC
Severity:
normal
Tags:
#1145198#5
Date:
2026-08-23 19:12:04 UTC
From:
To:
Hi,

The following vulnerability was published for podman.

CVE-2026-19730[0]:
| The 'podman quadlet install --replace' command opens the existing
| destination file with O_CREATE|O_WRONLY but omits O_TRUNC. When the
| initial reflink copy attempt fails (common on non-reflink-capable
| filesystems including many RHEL default XFS configurations), the
| fallback in ReflinkOrCopy uses io.Copy which performs a non-
| truncating write. If the original Quadlet is larger than the new
| Quadlet, the file is not truncated and content from the original is
| preserved. The command completes with no warning.  There is no risk
| of information leakage as the user already had access to the Quadlet
| in order to replace it, and in most cases, this would only lead to
| invalid Quadlet files. However, security-related options from the
| end of the old Quadlet could be included in the new Quadlet, and if
| the truncation resulted in a valid Quadlet file, this could result
| in undesirable behavior. For example, running podman quadlet install
| --replace to remove a single line from the end of a Quadlet -
| including security-sensitive content, like AddCapability - will
| fail, and the option will continue to be used. Further, with Volume
| Quadlets, this can include additional mounts which can cause content
| to be unintentionally exposed into containers. If, later, the image
| is updated then compromised content might be leaked to an attacker.
| The vulnerable code paths are in pkg/domain/infra/abi/quadlet.go
| (lines 338-360, O_CREATE|O_WRONLY without O_TRUNC) and
| vendor/go.podman.io/storage/pkg/fileutils/reflink_linux.go (lines
| 12-19, non-truncating io.Copy fallback).


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-19730
https://www.cve.org/CVERecord?id=CVE-2026-19730
[1] https://github.com/podman-container-tools/podman/security/advisories/GHSA-fx76-2j3w-2mx6

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore