Podman v5.8.4

v5.8.4
Fixed 1
  • Fix remote Podman client podman save command failure on Linux when using -f oci-dir or -f docker-dir arguments
Security 2
  • Address CVE-2026-57231 where malicious image Env entries could leak host environment variables into containers
  • Update golang.org/x/crypto library to v0.53.0 addressing CVE-2026-39830 and CVE-2026-42508
Security
  • This release addresses CVE-2026-57231, where a malicious image using malformed Env entries could cause host environment variables to leak into containers run based on the image, including the ability to use the * glob operator to leak large numbers of environment variables without knowing their exact names (GHSA-4hq8-gpf5-8p68).
  • The golang.org/x/crypto library has been updated to v0.53.0, addressing CVE-2026-39830 and CVE-2026-42508.
Bugfixes
  • Fixed a bug where the remote Podman client's podman save command would fail on Linux when using the -f oci-dir or -f docker-dir arguments.
View original

Upgraded? How did it go?

Discussion