Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Release podman-5.8.2-4.el10_2 ALSA-2026:37072

Open
#2,985 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
5/5
Estimated time
Over a week
Newbie friendliness
15/100
Issue type
Bug
Clarity
Needs clarification
Activity status
Quiet
Tech stack
go

Research direction

No repository files, tests, or entry points are named. Start with the listed CVEs, affected packages, and the two reported Podman bugs; the issue does not specify a code change or a completion check.

Written by the indexing model from the issue text.

Description

podman security, bug fix, and enhancement update
Severity: Important
Description
The podman tool manages pods, container images, and containers. It is part of the libpod library, which is for applications that use container pods. Container pods is a concept in Kubernetes.

Security Fix(es):

  • golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate (CVE-2026-39835)
  • golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters (CVE-2026-39829)
  • golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses (CVE-2026-39830)
  • golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions (CVE-2026-39832)
  • golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey (CVE-2026-42508)
  • golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass (CVE-2026-27136)
  • golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting (CVE-2026-25681)
  • podman: Podman: Information disclosure via malicious container image environment variables (CVE-2026-57231)

Bug Fix(es) and Enhancement(s):

  • podman does not clean up all files and leaves orphaned files consuming disk space [almalinux-10.2.z] (JIRA:AlmaLinux-173842)
  • [FJ10.2 Bug]: [REG]The "podman-remote save" command fails for rootless users. [almalinux-10.2.z] (JIRA:AlmaLinux-192440)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Affected packages:
podman-5.8.2-4.el10_2.x86_64
podman-docker-5.8.2-4.el10_2.noarch
podman-remote-5.8.2-4.el10_2.x86_64
podman-5.8.2-4.el10_2.s390x
podman-docker-5.8.2-4.el10_2.noarch
podman-remote-5.8.2-4.el10_2.s390x
podman-5.8.2-4.el10_2.ppc64le
podman-docker-5.8.2-4.el10_2.noarch
podman-remote-5.8.2-4.el10_2.ppc64le
podman-5.8.2-4.el10_2.aarch64
podman-docker-5.8.2-4.el10_2.noarch
podman-remote-5.8.2-4.el10_2.aarch64
podman-tests-5.8.2-4.el10_2.x86_64
podman-tests-5.8.2-4.el10_2.ppc64le
podman-tests-5.8.2-4.el10_2.aarch64
podman-tests-5.8.2-4.el10_2.s390x
podman-5.8.2-4.el10_2.x86_64_v2
podman-remote-5.8.2-4.el10_2.x86_64_v2
podman-tests-5.8.2-4.el10_2.x86_64_v2
podman-docker-5.8.2-4.el10_2.noarch

Dominant language
No language data
Stars
2
Forks
0
PR merge metrics
No merged PRs in 30d

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from AlmaLinux/updates

All issues in AlmaLinux/updates

Similar issues

More DevOps issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.