Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

Release rh-podman-desktop-1.1.2-1.el10_2 ALSA-2026:57590

未关闭
#3,334 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

还没有人认领这个 Issue。

评估

难度
5/5
预计耗时
一周以上
新手友好度
15/100
Issue 类型
功能
描述清晰度
需要澄清
活跃度
活跃
技术栈
go, javascript

调研方向

该 issue 未指定源文件或测试。首先检查受影响的软件包 rh-podman-desktop-1.1.2-1.el10_2.x86_64 及其 _v2 变体,以及 JIRA AlmaLinux-238929。完成的标准是将 RH Podman Desktop 1.1.2 发布到 AlmaLinux 10.2 Extensions,并包含列出的安全、错误修复和增强更新。

由索引模型根据 Issue 内容生成。

描述

rh-podman-desktop security, bug fix, and enhancement update
Severity: Important
Description
AlmaLinux build of Podman Desktop is a graphical tool for managing containers using Podman. It allows users to run, manage, and configure containers and container images using a desktop GUI.

Security Fix(es):

  • github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object (CVE-2026-34986)
  • ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input (CVE-2026-42338)
  • protobufjs: protobufjs: Denial of Service via crafted JSON descriptors (CVE-2026-45740)
  • ws: ws: Uninitialized memory disclosure via websocket.close() with TypedArray (CVE-2026-45736)
  • devalue: devalue: Excessive memory consumption via deserialization of sparse arrays (CVE-2026-42570)
  • tmp: path Traversal via unsanitized prefix/postfix enables directory escape (CVE-2026-44705)
  • form-data: form-data: Form field override via CRLF injection (CVE-2026-12143)
  • webpack-dev-server: webpack-dev-server: Information disclosure and denial of service via improper proxy configuration (CVE-2026-9595)
  • ws: ws: Denial of Service via memory exhaustion from small WebSocket fragments (CVE-2026-48779)
  • extract-zip: github.com/maxogden/extract-zip: extract-zip: Arbitrary file write and information disclosure via symlink validation bypass (CVE-2026-56876)
  • fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization (CVE-2026-13676)
  • brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity (CVE-2026-13149)
  • tar: Node-tar: Denial of Service via malformed tar archive header (CVE-2026-59874)
  • tar: node-tar: Denial of Service via crafted gzip bomb (CVE-2026-59873)
  • js-yaml: js-yaml: Denial of Service via crafted YAML documents (CVE-2026-59869)
  • protobufjs: protobufjs: Denial of Service via crafted .proto schema (CVE-2026-59877)
  • grpc-js: @grpc/grpc-js: Server crash via malformed HTTP/2 stream initiation (CVE-2026-48068)
  • linkify-it: linkify-it: Denial of Service via algorithmic complexity vulnerability (CVE-2026-48801)
  • dompurify: DOMPurify: Cross-site scripting vulnerability allows code execution (CVE-2026-49978)
  • brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function (CVE-2026-14257)
  • postcss: PostCSS: Information disclosure and denial of service via crafted CSS input (CVE-2026-45623)
  • postcss: PostCSS: Information disclosure via crafted sourceMappingURL (CVE-2026-69153)
  • brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation (CVE-2026-69152)
  • ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass (CVE-2026-69192)

Bug Fix(es) and Enhancement(s):

  • Release RH Podman Desktop 1.1.2 to AlmaLinux 10.2 Extensions (JIRA:AlmaLinux-238929)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Affected packages:
rh-podman-desktop-1.1.2-1.el10_2.x86_64
rh-podman-desktop-1.1.2-1.el10_2.x86_64_v2

主要语言
没有语言数据
星标
2
派生
0
PR 合并指标
30 天内没有已合并 PR

环境准备

  • 没有 Dockerfile 或 Docker Compose 文件
  • 没有 Pull Request 模板
  • 阅读贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

AlmaLinux/updates 的其他 Issue

查看 AlmaLinux/updates 的全部 Issue

相似的 Issue

更多 Desktop Dev Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。