目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2026-19730— Podman quadlet安装非截断写入保留已移除主机访问指令漏洞

一分钟漏洞结论

影响对象
Red Hat Red Hat Enterprise Linux 10
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

在 Podman 5.8.x 中发现了一个缺陷。 命令在打开现有目标文件时使用了 标志,但遗漏了 标志。当初始的引用复制(reflink copy)尝试失败时(在非支持引用复制的文件系统上常见,包括许多 RHEL 默认配置的 XFS), 中的回退机制会采用 ,后者执行的是非截断式写入。如果原始 Quadlet 文件大于新 Quadlet 文件,文件将不会被截断,原始文件的内容将被保留。该命令完成时不会发出任何警告。 虽然不存在信息泄露风险,因为用户已经有权访问要替换的 Quadlet 文件,并且在大多数情况下这只会

CVSS 4.2 · Medium EPSS 0.16% · P5

可能的 ATT&CK 技术 1 AI

T1557 · Adversary-in-the-Middle

影响版本矩阵 15

厂商产品 版本范围状态
Red Hat Red Hat Ansible Automation Platform 2 全部 unaffected
全部 unaffected
全部 unaffected
全部 unaffected
Red Hat Red Hat Enterprise Linux 10 7:5.8.2-9.el10_2< * unaffected
Red Hat Red Hat Enterprise Linux 8 全部 unaffected
Red Hat Red Hat Enterprise Linux 9 6:5.8.2-7.el9_8< * unaffected
Red Hat Red Hat Hardened Images 全部 affected
Red Hat Red Hat OpenShift Container Platform 4 全部 unaffected
Red Hat Red Hat OpenShift Dev Spaces 全部 unaffected
全部 unaffected
全部 unaffected
Red Hat Red Hat OpenShift Virtualization 4 全部 unaffected
Red Hat Red Hat Quay 3 全部 unaffected
全部 unaffected
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-19730 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Podman: podman: quadlet install --replace non-truncating write retains removed host-access directives
来源: CVE Program / CVE List V5
Vulnerability Description
The 'podman quadlet install --replace' command opens the existing destination file with O_CREATE|O_WRONLY but omits O_TRUNC. When the initial reflink copy attempt fails (common on non-reflink-capable filesystems including many RHEL default XFS configurations), the fallback in ReflinkOrCopy uses io.Copy which performs a non-truncating write. If the original Quadlet is larger than the new Quadlet, the file is not truncated and content from the original is preserved. The command completes with no warning. There is no risk of information leakage as the user already had access to the Quadlet in order to replace it, and in most cases, this would only lead to invalid Quadlet files. However, security-related options from the end of the old Quadlet could be included in the new Quadlet, and if the truncation resulted in a valid Quadlet file, this could result in undesirable behavior. For example, running podman quadlet install --replace to remove a single line from the end of a Quadlet - including security-sensitive content, like AddCapability - will fail, and the option will continue to be used. Further, with Volume Quadlets, this can include additional mounts which can cause content to be unintentionally exposed into containers. If, later, the image is updated then compromised content might be leaked to an attacker. The vulnerable code paths are in pkg/domain/infra/abi/quadlet.go (lines 338-360, O_CREATE|O_WRONLY without O_TRUNC) and vendor/go.podman.io/storage/pkg/fileutils/reflink_linux.go (lines 12-19, non-truncating io.Copy fallback).
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L
来源: CVE Program / CVE List V5
Vulnerability Type
清理环节不完整
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
Red Hat Red Hat Enterprise Linux 10 7:5.8.2-9.el10_2 ~ * cpe:/o:redhat:enterprise_linux:10.2
Red Hat Red Hat Enterprise Linux 9 6:5.8.2-7.el9_8 ~ * cpe:/a:redhat:enterprise_linux:9::appstream
Red Hat Red Hat Ansible Automation Platform 2 - cpe:/a:redhat:ansible_automation_platform:2
Red Hat Red Hat Ansible Automation Platform 2 - cpe:/a:redhat:ansible_automation_platform:2
Red Hat Red Hat Ansible Automation Platform 2 - cpe:/a:redhat:ansible_automation_platform:2
Red Hat Red Hat Ansible Automation Platform 2 - cpe:/a:redhat:ansible_automation_platform:2
Red Hat Red Hat Enterprise Linux 8 - cpe:/o:redhat:enterprise_linux:8
Red Hat Red Hat Hardened Images - cpe:/a:redhat:hummingbird:1
Red Hat Red Hat OpenShift Container Platform 4 - cpe:/a:redhat:openshift:4
Red Hat Red Hat OpenShift Dev Spaces - cpe:/a:redhat:openshift_devspaces:3
Red Hat Red Hat OpenShift Dev Spaces - cpe:/a:redhat:openshift_devspaces:3
Red Hat Red Hat OpenShift Dev Spaces - cpe:/a:redhat:openshift_devspaces:3
Red Hat Red Hat OpenShift Virtualization 4 - cpe:/a:redhat:container_native_virtualization:4
Red Hat Red Hat Quay 3 - cpe:/a:redhat:quay:3
Red Hat Red Hat Quay 3 - cpe:/a:redhat:quay:3

二、漏洞 CVE-2026-19730 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-19730 的情报信息

请登录查看更多情报信息。

CVE-2026-19730 厂商安全公告 (4)

CVE-2026-19730 其他参考 (1)

同批安全公告 · Red Hat · 2026-08-13 · 共 6 条

CVE-2026-73266 7.1 HIGH Stolostron clusterclaims-controller 服务端请求伪造漏洞
CVE-2026-73583 6.6 MEDIUM Red Hat sblim-sfcb 缓冲区错误漏洞
CVE-2026-18728 6.5 MEDIUM Open-iSCSI 数字错误漏洞
CVE-2026-73585 6.3 MEDIUM Red Hat sblim-cmpi-base 资源管理错误漏洞
CVE-2026-73584 6.3 MEDIUM Red Hat sblim-sfcb 资源管理错误漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2026-19730

暂无评论


发表评论