#1149955 podman: CVE-2026-94603

Package:
src:podman
Source:
src:podman
Submitter:
Salvatore Bonaccorso
Date:
2026-10-08 21:55:03 UTC
Severity:
normal
Tags:
#1149955#5
Date:
2026-10-04 18:57:49 UTC
From:
To:
Hi,

The following vulnerability was published for podman.

CVE-2026-94603[0]:
| The `podman run` command can be instructed to disable almost all
| sandboxing - including user-requested sandboxing - by image annotation


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-94603
https://www.cve.org/CVERecord?id=CVE-2026-94603
[1] https://github.com/podman-container-tools/podman/security/advisories/GHSA-2cvf-wqm6-wr9g

Regards,
Salvatore

#1149955#10
Date:
2026-10-08 19:21:46 UTC
From:
To:
Hello,

Bug #1149955 in libpod reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/go-team/packages/podman/-/commit/a7d8f34611c11037d08325a91b70400bca8f6b07
------------------------------------------------------------------------
debian/patches: Add patch for CVE-2026-94603 (Closes: #1149955)

Remove support for running checkpoint images via 'podman run'.
Images with checkpoint annotations could otherwise bypass user-specified
sandboxing options.
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1149955

#1149955#15
Date:
2026-10-08 21:52:24 UTC
From:
To:
Hello,

Bug #1149955 in libpod reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/go-team/packages/podman/-/commit/a7d8f34611c11037d08325a91b70400bca8f6b07
------------------------------------------------------------------------
debian/patches: Add patch for CVE-2026-94603 (Closes: #1149955)

Remove support for running checkpoint images via 'podman run'.
Images with checkpoint annotations could otherwise bypass user-specified
sandboxing options.
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1149955