Release rh-podman-desktop-1.1.2-1.el10_2 ALSA-2026:57590
还没有人认领这个 Issue。
评估
- 难度
- 5/5
- 预计耗时
- 一周以上
- 新手友好度
- 15/100
- Issue 类型
- 功能
- 描述清晰度
- 需要澄清
- 活跃度
- 活跃
- 技术栈
- go, javascript
- 领域
- desktop-dev, release, security
调研方向
该 issue 未指定源文件或测试。首先检查受影响的软件包 rh-podman-desktop-1.1.2-1.el10_2.x86_64 及其 _v2 变体,以及 JIRA AlmaLinux-238929。完成的标准是将 RH Podman Desktop 1.1.2 发布到 AlmaLinux 10.2 Extensions,并包含列出的安全、错误修复和增强更新。
由索引模型根据 Issue 内容生成。
描述
rh-podman-desktop security, bug fix, and enhancement update
Severity: Important
Description
AlmaLinux build of Podman Desktop is a graphical tool for managing containers using Podman. It allows users to run, manage, and configure containers and container images using a desktop GUI.
Security Fix(es):
- github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object (CVE-2026-34986)
- ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input (CVE-2026-42338)
- protobufjs: protobufjs: Denial of Service via crafted JSON descriptors (CVE-2026-45740)
- ws: ws: Uninitialized memory disclosure via
websocket.close()withTypedArray(CVE-2026-45736) - devalue: devalue: Excessive memory consumption via deserialization of sparse arrays (CVE-2026-42570)
- tmp: path Traversal via unsanitized prefix/postfix enables directory escape (CVE-2026-44705)
- form-data: form-data: Form field override via CRLF injection (CVE-2026-12143)
- webpack-dev-server: webpack-dev-server: Information disclosure and denial of service via improper proxy configuration (CVE-2026-9595)
- ws: ws: Denial of Service via memory exhaustion from small WebSocket fragments (CVE-2026-48779)
- extract-zip: github.com/maxogden/extract-zip: extract-zip: Arbitrary file write and information disclosure via symlink validation bypass (CVE-2026-56876)
- fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization (CVE-2026-13676)
- brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity (CVE-2026-13149)
- tar: Node-tar: Denial of Service via malformed tar archive header (CVE-2026-59874)
- tar: node-tar: Denial of Service via crafted gzip bomb (CVE-2026-59873)
- js-yaml: js-yaml: Denial of Service via crafted YAML documents (CVE-2026-59869)
- protobufjs: protobufjs: Denial of Service via crafted .proto schema (CVE-2026-59877)
- grpc-js: @grpc/grpc-js: Server crash via malformed HTTP/2 stream initiation (CVE-2026-48068)
- linkify-it: linkify-it: Denial of Service via algorithmic complexity vulnerability (CVE-2026-48801)
- dompurify: DOMPurify: Cross-site scripting vulnerability allows code execution (CVE-2026-49978)
- brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function (CVE-2026-14257)
- postcss: PostCSS: Information disclosure and denial of service via crafted CSS input (CVE-2026-45623)
- postcss: PostCSS: Information disclosure via crafted sourceMappingURL (CVE-2026-69153)
- brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation (CVE-2026-69152)
- ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass (CVE-2026-69192)
Bug Fix(es) and Enhancement(s):
- Release RH Podman Desktop 1.1.2 to AlmaLinux 10.2 Extensions (JIRA:AlmaLinux-238929)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected packages:
rh-podman-desktop-1.1.2-1.el10_2.x86_64
rh-podman-desktop-1.1.2-1.el10_2.x86_64_v2
- 主要语言
- 没有语言数据
- 星标
- 2
- 派生
- 0
- PR 合并指标
- 30 天内没有已合并 PR
环境准备
- 没有 Dockerfile 或 Docker Compose 文件
- 没有 Pull Request 模板
- 阅读贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
AlmaLinux/updates 的其他 Issue
-
难度 1/5 1 小时以内 新手友好度 85/100
-
难度 1/5 1 小时以内 新手友好度 60/100
-
难度 2/5 1-3 小时 新手友好度 62/100
-
难度 4/5 3-5 天 新手友好度 30/100
-
难度 3/5 1-2 天 新手友好度 52/100
查看 AlmaLinux/updates 的全部 Issue
相似的 Issue
-
难度 2/5 1-3 小时 新手友好度 76/100
维护者通常 1 天内回复
-
[docs] Media elements cannot load from a custom protocol (video/audio report MEDIA_ERR_SRC_NOT_SUPPORTED)可能已有人在做 @vst93 今天认领。 未关闭
难度 2/5 1-3 小时 新手友好度 68/100
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 77/100
维护者通常 1 天内回复
-
enhancement user-priority/P2
难度 2/5 1-3 小时 新手友好度 65/100
维护者通常 1 天内回复
-
难度 1/5 1-3 小时 新手友好度 85/100
NousResearch/hermes-agent#134960 ·
维护者通常 1 天内回复