Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-19730— Podman: podman: quadlet install --replace non-truncating write retains removed host-access directives

Quick assessment

Affected
Red Hat Red Hat Enterprise Linux 10
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Podman 5.8.x 中发现了一个缺陷。 命令在打开现有目标文件时使用了 标志,但遗漏了 标志。当初始的引用复制(reflink copy)尝试失败时(在非支持引用复制的文件系统上常见,包括许多 RHEL 默认配置的 XFS), 中的回退机制会采用 ,后者执行的是非截断式写入。如果原始 Quadlet 文件大于新 Quadlet 文件,文件将不会被截断,原始文件的内容将被保留。该命令完成时不会发出任何警告。 虽然不存在信息泄露风险,因为用户已经有权访问要替换的 Quadlet 文件,并且在大多数情况下这只会

CVSS 4.2 · Medium EPSS 0.16% · P5

Possible ATT&CK Techniques 1 AI

T1557 · Adversary-in-the-Middle

Affected Version Matrix 15

VendorProduct Version RangeStatus
Red Hat Red Hat Ansible Automation Platform 2 any unaffected
any unaffected
any unaffected
any unaffected
Red Hat Red Hat Enterprise Linux 10 7:5.8.2-9.el10_2< * unaffected
Red Hat Red Hat Enterprise Linux 8 any unaffected
Red Hat Red Hat Enterprise Linux 9 6:5.8.2-7.el9_8< * unaffected
Red Hat Red Hat Hardened Images any unaffected
Red Hat Red Hat OpenShift Container Platform 4 any unaffected
Red Hat Red Hat OpenShift Dev Spaces any unaffected
any unaffected
any unaffected
Red Hat Red Hat OpenShift Virtualization 4 any unaffected
Red Hat Red Hat Quay 3 any unaffected
any unaffected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-19730

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Podman: podman: quadlet install --replace non-truncating write retains removed host-access directives
Source: CVE Program / CVE List V5
Vulnerability Description
The 'podman quadlet install --replace' command opens the existing destination file with O_CREATE|O_WRONLY but omits O_TRUNC. When the initial reflink copy attempt fails (common on non-reflink-capable filesystems including many RHEL default XFS configurations), the fallback in ReflinkOrCopy uses io.Copy which performs a non-truncating write. If the original Quadlet is larger than the new Quadlet, the file is not truncated and content from the original is preserved. The command completes with no warning. There is no risk of information leakage as the user already had access to the Quadlet in order to replace it, and in most cases, this would only lead to invalid Quadlet files. However, security-related options from the end of the old Quadlet could be included in the new Quadlet, and if the truncation resulted in a valid Quadlet file, this could result in undesirable behavior. For example, running podman quadlet install --replace to remove a single line from the end of a Quadlet - including security-sensitive content, like AddCapability - will fail, and the option will continue to be used. Further, with Volume Quadlets, this can include additional mounts which can cause content to be unintentionally exposed into containers. If, later, the image is updated then compromised content might be leaked to an attacker. The vulnerable code paths are in pkg/domain/infra/abi/quadlet.go (lines 338-360, O_CREATE|O_WRONLY without O_TRUNC) and vendor/go.podman.io/storage/pkg/fileutils/reflink_linux.go (lines 12-19, non-truncating io.Copy fallback).
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
清理环节不完整
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat Enterprise Linux 10 7:5.8.2-9.el10_2 ~ * cpe:/o:redhat:enterprise_linux:10.2
Red Hat Red Hat Enterprise Linux 9 6:5.8.2-7.el9_8 ~ * cpe:/a:redhat:enterprise_linux:9::appstream
Red Hat Red Hat Ansible Automation Platform 2 - cpe:/a:redhat:ansible_automation_platform:2
Red Hat Red Hat Ansible Automation Platform 2 - cpe:/a:redhat:ansible_automation_platform:2
Red Hat Red Hat Ansible Automation Platform 2 - cpe:/a:redhat:ansible_automation_platform:2
Red Hat Red Hat Ansible Automation Platform 2 - cpe:/a:redhat:ansible_automation_platform:2
Red Hat Red Hat Enterprise Linux 8 - cpe:/o:redhat:enterprise_linux:8
Red Hat Red Hat Hardened Images - cpe:/a:redhat:hummingbird:1
Red Hat Red Hat OpenShift Container Platform 4 - cpe:/a:redhat:openshift:4
Red Hat Red Hat OpenShift Dev Spaces - cpe:/a:redhat:openshift_devspaces:3
Red Hat Red Hat OpenShift Dev Spaces - cpe:/a:redhat:openshift_devspaces:3
Red Hat Red Hat OpenShift Dev Spaces - cpe:/a:redhat:openshift_devspaces:3
Red Hat Red Hat OpenShift Virtualization 4 - cpe:/a:redhat:container_native_virtualization:4
Red Hat Red Hat Quay 3 - cpe:/a:redhat:quay:3
Red Hat Red Hat Quay 3 - cpe:/a:redhat:quay:3

II. Public POCs for CVE-2026-19730

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-19730

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-19730 (4)

Other References for CVE-2026-19730 (1)

Same Patch Batch · Red Hat · 2026-08-13 · 6 CVEs total

CVE-2026-73266 7.1 HIGH Clusterclaims-controller: confused deputy: tenant-controlled clusterclaim labels propagate
CVE-2026-73583 6.6 MEDIUM Sblim-sfcb: unsafe deserialization in sblim-sfcb provider-manager ipc allows out-of-bounds
CVE-2026-18728 6.5 MEDIUM Open-iscsi: open-iscsi: integer underflow in iscsiuio ipv4 dhcp parsing
CVE-2026-73585 6.3 MEDIUM Sblim-cmpi-base: insecure temporary file creation in sblim-cmpi-base provider registration
CVE-2026-73584 6.3 MEDIUM Sblim-sfcb: sblim-sfcb: privileged file corruption and denial of service via insecure temp

IV. Related Vulnerabilities

V. Comments for CVE-2026-19730

No comments yet


Leave a comment