在 Podman 5.8.x 中发现了一个缺陷。 命令在打开现有目标文件时使用了 标志,但遗漏了 标志。当初始的引用复制(reflink copy)尝试失败时(在非支持引用复制的文件系统上常见,包括许多 RHEL 默认配置的 XFS), 中的回退机制会采用 ,后者执行的是非截断式写入。如果原始 Quadlet 文件大于新 Quadlet 文件,文件将不会被截断,原始文件的内容将被保留。该命令完成时不会发出任何警告。 虽然不存在信息泄露风险,因为用户已经有权访问要替换的 Quadlet 文件,并且在大多数情况下这只会
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Ansible Automation Platform 2 | any |
unaffected |
any |
unaffected | ||
any |
unaffected | ||
any |
unaffected | ||
| Red Hat | Red Hat Enterprise Linux 10 | 7:5.8.2-9.el10_2< * |
unaffected |
| Red Hat | Red Hat Enterprise Linux 8 | any |
unaffected |
| Red Hat | Red Hat Enterprise Linux 9 | 6:5.8.2-7.el9_8< * |
unaffected |
| Red Hat | Red Hat Hardened Images | any |
unaffected |
| Red Hat | Red Hat OpenShift Container Platform 4 | any |
unaffected |
| Red Hat | Red Hat OpenShift Dev Spaces | any |
unaffected |
any |
unaffected | ||
any |
unaffected | ||
| Red Hat | Red Hat OpenShift Virtualization 4 | any |
unaffected |
| Red Hat | Red Hat Quay 3 | any |
unaffected |
any |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | 7:5.8.2-9.el10_2 ~ * |
cpe:/o:redhat:enterprise_linux:10.2
|
|
| Red Hat | Red Hat Enterprise Linux 9 | 6:5.8.2-7.el9_8 ~ * |
cpe:/a:redhat:enterprise_linux:9::appstream
|
|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Hardened Images | - |
cpe:/a:redhat:hummingbird:1
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| Red Hat | Red Hat OpenShift Dev Spaces | - |
cpe:/a:redhat:openshift_devspaces:3
|
|
| Red Hat | Red Hat OpenShift Dev Spaces | - |
cpe:/a:redhat:openshift_devspaces:3
|
|
| Red Hat | Red Hat OpenShift Dev Spaces | - |
cpe:/a:redhat:openshift_devspaces:3
|
|
| Red Hat | Red Hat OpenShift Virtualization 4 | - |
cpe:/a:redhat:container_native_virtualization:4
|
|
| Red Hat | Red Hat Quay 3 | - |
cpe:/a:redhat:quay:3
|
|
| Red Hat | Red Hat Quay 3 | - |
cpe:/a:redhat:quay:3
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-73266 | 7.1 HIGH | Clusterclaims-controller: confused deputy: tenant-controlled clusterclaim labels propagate |
| CVE-2026-73583 | 6.6 MEDIUM | Sblim-sfcb: unsafe deserialization in sblim-sfcb provider-manager ipc allows out-of-bounds |
| CVE-2026-18728 | 6.5 MEDIUM | Open-iscsi: open-iscsi: integer underflow in iscsiuio ipv4 dhcp parsing |
| CVE-2026-73585 | 6.3 MEDIUM | Sblim-cmpi-base: insecure temporary file creation in sblim-cmpi-base provider registration |
| CVE-2026-73584 | 6.3 MEDIUM | Sblim-sfcb: sblim-sfcb: privileged file corruption and denial of service via insecure temp |
No comments yet