Zum Inhalt springen

Podman Release Notes

11 Einträge aus 1 Quelle. Zuletzt aktualisiert:

Folge Podman, um die Release Notes in deinen Feed zu holen.

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Podman

Podman 6.1.3: Fix für CVE-2026-94603, Checkpoint-Images entfernt

Podman 6.1.3 behebt CVE-2026-94603, bei dem podman run auf einem Checkpoint-Image beim Erstellen des Containers jegliches Sandboxing deaktivieren konnte, und entfernt als Breaking Change die Unterstützung für Checkpoint-Images in podman run.

Security

  • This release addresses CVE-2026-94603, where a podman run on a checkpoint image (any image with the io.podman.annotations.checkpoint.runtime.name annotation) could disable all sandboxing, including sandboxing specified by the user, when the container was created.

Breaking Changes

  • Removed support for checkpoint images in podman run due to serious security concerns with the different security models of running images and running checkpoints. Checkpoints ignore user-specified security configuration and are very difficult to run safely.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Podman

Podman 5.8.8: Fix für CVE-2026-94603, Checkpoint-Images entfernt

Podman 5.8.8 behebt CVE-2026-94603, bei dem podman run auf einem Checkpoint-Image das Sandboxing deaktivieren konnte, und entfernt als Breaking Change die Unterstützung für Checkpoint-Images in podman run.

  • This release addresses CVE-2026-94603, where a podman run on a checkpoint image (any image with the io.podman.annotations.checkpoint.runtime.name annotation) could disable all sandboxing, including sandboxing specified by the user, when the container was created.

Breaking Changes

  • Removed support for checkpoint images in podman run due to serious security concerns with the different security models of running images and running checkpoints. Checkpoints ignore user-specified security configuration and are very difficult to run safely.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Podman

Podman 5.8.7: Fix für CVE-2025-11395 und zwei weitere CVEs

Podman 5.8.7 behebt CVE-2025-11395, bei dem manipulierte Images (podman load) oder Volumes (podman volume import) Dateien auf dem Host überschreiben konnten, behandelt zwei weitere CVEs und aktualisiert Buildah, Common, Image und Storage.

Security

  • This release addresses (CVE-2025-11395), where importing images containing crafted layer tarballs with the podman load command, or importing volumes containing crafted symlinks with podman volume import, allows overwriting files on the host.
  • This release also addresses CVE-2026-79699 and CVE-2026-79705, though we do not believe these CVEs are exploitable through the Podman command line.

Misc

  • Updated Buildah to v1.43.4
  • Updated Common to v0.67.2
  • Updated Image to v5.39.3
  • Updated Storage to v1.62.1

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Podman

Podman 6.1.2: Fix für CVE-2025-11395 und zwei weitere CVEs

Podman 6.1.2 behebt CVE-2025-11395, bei dem manipulierte Images (podman load) oder Volumes (podman volume import) Dateien auf dem Host überschreiben konnten, behandelt zwei weitere CVEs und aktualisiert Buildah, Common, Image und Storage.

Security

  • This release addresses (CVE-2025-11395), where importing images containing crafted layer tarballs with the podman load command, or importing volumes containing crafted symlinks with podman volume import, allows overwriting files on the host.
  • This release also addresses CVE-2026-79699 and CVE-2026-79705, though we do not believe these CVEs are exploitable through the Podman command line.

Misc

  • Updated Buildah to v1.45.1
  • Updated Common to v0.69.2
  • Updated Image to v5.41.2
  • Updated Storage to v1.64.1

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Podman

Podman 6.1.1: Fix für CVE-2026-17106, rootlessport-Binding repariert

Podman 6.1.1 behebt CVE-2026-17106, bei dem ein manipuliertes Tar-Archiv über bösartige Links außerhalb des Extraktionsverzeichnisses schreiben konnte, und repariert das rootlessport-Binden mit -p 0.0.0.0:... -p [::]:..., sodass Podman Machine unter WSL Ports wieder korrekt weiterleitet.

Security

  • This release addresses CVE-2026-17106, where a crafted tar archive could write outside the extraction directory through the use of malicious links (GHSA-hfg8-hc9c-6c3h).

Bugfixes

  • Fixed broken rootlessport bind behavior with -p 0.0.0.0:... -p [::]:... which failed instead of binding both v4 and v6 separately. Podman Machine on WSL should now correctly forward ports again by binding separate IPv4 and IPv6 sockets to make the WSL forwarder logic work again (#29377).

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Podman

Podman 5.8.6: Fix für CVE-2026-19730 bei quadlet install --replace

Podman 5.8.6 behebt CVE-2026-19730, bei dem podman quadlet install --replace die ersetzte Datei nicht kürzte und dadurch Inhalte der Originaldatei erhalten blieben.

Security

  • This release addressed CVE-2026-19730 where the podman quadlet install --replace command did not truncate the file being replaced, meaning replacing a longer file with a shorter one would result in content from the original file incorrectly being retained.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Podman

Podman 6.1.0: Neue Befehle, Optionen und Quadlet-Schlüssel ImageVolume=

Podman 6.1.0 führt die neuen Befehle podman volume rename und podman machine restart, die Optionen podman network rm --ignore sowie --retry und --retry-delay für podman manifest push, den Quadlet-Schlüssel ImageVolume= und die Erzeugung von livenessProbe durch podman generate kube ein.

Features

  • A new command has been added, podman volume rename, to allow renaming volumes. Volumes created using volume drivers and volumes that are currently used by a container cannot be renamed (#28189).
  • A new command has been added, podman machine restart, to allow easy restart of VMs managed by podman machine (#28366).
  • The podman network rm command now includes a new option, --ignore, which suppresses errors when attempting to remove networks that do not exist (#28363).
  • The podman manifest push command now includes two new options, --retry and --retry-delay, which allow pushes to be automatically retried on failure (#28590).
  • Quadlet .container units now support a new key, ImageVolume=, to configure how volumes from images are handled (#28875).
  • The podman generate kube command now includes support for generating container healthchecks as a livenessProbe (#22095). …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Podman

Podman 6.1.0-rc1: Release Candidate mit neuen Befehlen und Optionen

Podman 6.1.0-rc1 bringt als Release Candidate die neuen Befehle podman volume rename und podman machine restart, die Optionen podman network rm --ignore sowie --retry und --retry-delay für podman manifest push, den Quadlet-Schlüssel ImageVolume= und livenessProbe-Support in podman generate kube.

Features

  • A new command has been added, podman volume rename, to allow renaming volumes. Volumes created using volume drivers and volumes that are currently used by a container cannot be renamed (#28189).
  • A new command has been added, podman machine restart, to allow easy restart of VMs managed by podman machine (#28366).
  • The podman network rm command now includes a new option, --ignore, which suppresses errors when attempting to remove networks that do not exist (#28363).
  • The podman manifest push command now includes two new options, --retry and --retry-delay, which allow pushes to be automatically retried on failure (#28590).
  • Quadlet .container units now support a new key, ImageVolume=, to configure how volumes from images are handled (#28875).
  • The podman generate kube command now includes support for generating container healthchecks as a livenessProbe (#22095).

Changes …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Podman

Podman 6.0.2: Fixes für WSL, Windows-Installer und Remote-Client

Podman 6.0.2 behebt Fehler beim Aufräumen von WSL-VMs nach fehlgeschlagenem podman machine init, beim Windows-Installer mit Installation für alle Benutzer und beim Remote-Client auf Linux-Systemen ohne Cgroups v2 und aktualisiert Buildah auf v1.44.1.

Bugfixes

  • Fixed a bug where podman machine VMs created by the WSL provider on Windows were not properly cleaned up if the podman machine init command failed (#27036).
  • Fixed a bug where the Windows installer for Podman would, when installing for all users, incorrectly modify the path of only the user installing Podman (#29160).
  • Fixed a bug where the remote Podman client would throw errors when run on a Linux system that was not using Cgroups v2 (#29241).

Misc

  • Updated Buildah to v1.44.1

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Podman

Podman 6.0.1: Mehrere Fehlerbehebungen für libkrun, Windows und WSL

Podman 6.0.1 behebt mehrere Fehler, darunter unbeabsichtigte Abschaltungen von libkrun-VMs auf dem Mac, fehlschlagendes podman machine init unter Windows, nicht angezeigte OCI-Runtime-Fehlermeldungen, ein defektes podman machine os upgrade, nicht gecachte Standard-Images und nicht startende rootful WSL-VMs.

Bugfixes

  • Fixed a bug where Podman Machine VMs on Mac using the libkrun provider could be regularly turned off by a port-scanning process on the host unintentionally commanding the VM to shut down.
  • Fixed a bug where the podman machine init command would fail on Windows hosts when using the hyperv provider when WSL was not installed (#29053).
  • Fixed a bug where the podman machine init command would fail on Windows hosts when using the wsl provider when the user was a Hyper-V admin but Hyper-V is disabled (#29138).
  • Fixed a bug where error messages from the OCI runtime were sometimes not displayed when --log-level=debug was passed to Podman.
  • Fixed a bug where the podman machine os upgrade command did not function properly (#29085).
  • Fixed a bug where the default image used by podman machine was not being properly cached (#29090).
  • Fixed a bug where rootful Podman Machine VMs on Windows using the wsl provider would fail to start (#29003). …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Podman

Podman 5.8.5: Ungewolltes Herunterfahren von libkrun-VMs auf dem Mac behoben

Podman 5.8.5 behebt einen Fehler, durch den Podman-Machine-VMs mit libkrun-Provider auf dem Mac von einem Port-Scanning-Prozess des Hosts unbeabsichtigt heruntergefahren werden konnten.

Bugfixes

  • Fixed a bug where Podman Machine VMs on Mac using the libkrun provider could be regularly turned off by a port-scanning process on the host unintentionally commanding the VM to shut down.

Originalquelle(öffnet in neuem Tab)Problem melden