- What: Security, bug fix, and enhancement update for podman
- Impact: Red Hat Enterprise Linux 10 users need to apply the update
Red Hat Product Errata RHSA-2026:37072 - Security Advisory Issued: 2026-07-09 Updated: 2026-07-09 RHSA-2026:37072 - Security Advisory Overview Updated Packages Synopsis Important: podman security, bug fix, and enhancement update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for podman is now available for Red Hat Enterprise Linux 10. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The podman tool manages pods, container images, and containers. It is part of the libpod library, which is for applications that use container pods. Container pods is a concept in Kubernetes. Security Fix(es): golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate (CVE-2026-39835) golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters (CVE-2026-39829) golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses (CVE-2026-39830) golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions (CVE-2026-39832) golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey (CVE-2026-42508) golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass (CVE-2026-27136) golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting (CVE-2026-25681) podman: Podman: Information disclosure via malicious container image environment variables (CVE-2026-57231) Bug Fix(es) and Enhancement(s): podman does not clean up all files and leaves orphaned files consuming disk space [rhel-10.2.z] (JIRA:RHEL-173842) [FJ10.2 Bug]: [REG]The "podman-remote save" command fails for rootless users. [rhel-10.2.z] (JIRA:RHEL-192440) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 10 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 x86_64 Red Hat Enterprise Linux for IBM z Systems 10 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 s390x Red Hat Enterprise Linux for Power, little endian 10 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2 ppc64le Red Hat Enterprise Linux for ARM 64 10 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.2 aarch64 Red Hat CodeReady Linux Builder for x86_64 10 x86_64 Red Hat CodeReady Linux Builder for Power, little endian 10 ppc64le Red Hat CodeReady Linux Builder for ARM 64 10 aarch64 Red Hat CodeReady Linux Builder for IBM z Systems 10 s390x Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 10.2 x86_64 Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 10.2 ppc64le Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 10.2 s390x Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 10.2 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.2 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.2 s390x Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.2 ppc64le Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.2 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 10.2 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 10.2 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 10.2 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 10.2 s390x Fixes BZ - 2480680 - CVE-2026-39835 golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate BZ - 2480681 - CVE-2026-39829 golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters BZ - 2480684 - CVE-2026-39830 golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses BZ - 2480685 - CVE-2026-39832 golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions BZ - 2480688 - CVE-2026-42508 golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey BZ - 2480757 - CVE-2026-27136 golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass BZ - 2480761 - CVE-2026-25681 golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting BZ - 2493620 - CVE-2026-57231 podman: Podman: Information disclosure via malicious container image environment variables CVEs CVE-2026-25681 CVE-2026-27136 CVE-2026-39829 CVE-2026-39830 CVE-2026-39832 CVE-2026-39835 CVE-2026-42508 CVE-2026-57231 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 10 SRPM podman-5.8.2-4.el10_2.src.rpm SHA-256: 974d01237064a9dbb91b2d62d58f02d2525953026b8ef032925c6cd78d4ede99 x86_64 podman-5.8.2-4.el10_2.x86_64.rpm SHA-256: a7feee8d20ffe971b8b87c88a43cb69674a71e615ac553e0b2e34b1b92ebe082 podman-debuginfo-5.8.2-4.el10_2.x86_64.rpm SHA-256: f5007e842ca4bc84cfa013ce1b02cdc184a04de0d68e7587f8793b434e5660af podman-debugsource-5.8.2-4.el10_2.x86_64.rpm SHA-256: 9885d311316baad4b01534306e2c287e4f4e2ab1e76bd928f2c33d17bca179d3 podman-docker-5.8.2-4.el10_2.noarch.rpm SHA-256: f58363ca76057718b82d86bcdc9f0c895f64e62a5583e3a56aeb97c89e8deb39 podman-remote-5.8.2-4.el10_2.x86_64.rpm SHA-256: e84fd6d4e2500a712b5d45113db6ffde73889c1325c9bc7ea6b21cd6f2cae8dd podman-remote-debuginfo-5.8.2-4.el10_2.x86_64.rpm SHA-256: 9560e31125546f6bc16c381884c1abfbb7bec2032cdb2d827fa95911f5039da9 podman-tests-debuginfo-5.8.2-4.el10_2.x86_64.rpm SHA-256: dc73da6cdcaa483183df9ce71a742294475531b8a7a9421f3c76b2086857ea9f Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 SRPM podman-5.8.2-4.el10_2.src.rpm SHA-256: 974d01237064a9dbb91b2d62d58f02d2525953026b8ef032925c6cd78d4ede99 x86_64 podman-5.8.2-4.el10_2.x86_64.rpm SHA-256: a7feee8d20ffe971b8b87c88a43cb69674a71e615ac553e0b2e34b1b92ebe082 podman-debuginfo-5.8.2-4.el10_2.x86_64.rpm SHA-256: f5007e842ca4bc84cfa013ce1b02cdc184a04de0d68e7587f8793b434e5660af podman-debugsource-5.8.2-4.el10_2.x86_64.rpm SHA-256: 9885d311316baad4b01534306e2c287e4f4e2ab1e76bd928f2c33d17bca179d3 podman-docker-5.8.2-4.el10_2.noarch.rpm SHA-256: f58363ca76057718b82d86bcdc9f0c895f64e62a5583e3a56aeb97c89e8deb39 podman-remote-5.8.2-4.el10_2.x86_64.rpm SHA-256: e84fd6d4e2500a712b5d45113db6ffde73889c1325c9bc7ea6b21cd6f2cae8dd podman-remote-debuginfo-5.8.2-4.el10_2.x86_64.rpm SHA-256: 9560e31125546f6bc16c381884c1abfbb7bec2032cdb2d827fa95911f5039da9 podman-tests-debuginfo-5.8.2-4.el10_2.x86_64.rpm SHA-256: dc73da6cdcaa483183df9ce71a742294475531b8a7a9421f3c76b2086857ea9f Red Hat Enterprise Linux for IBM z Systems 10 SRPM podman-5.8.2-4.el10_2.src.rpm SHA-256: 974d01237064a9dbb91b2d62d58f02d2525953026b8ef032925c6cd78d4ede99 s390x podman-5.8.2-4.el10_2.s390x.rpm SHA-256: d5c6904b3fea73d89f3943c2a2f3421818aa0e2644fdff0d65d860f39772d54d podman-debuginfo-5.8.2-4.el10_2.s390x.rpm SHA-256: eafef23b74d765f3229553baf5661d3e025efb43e048d1ab49418aec73992a2c podman-debugsource-5.8.2-4.el10_2.s390x.rpm SHA-256: 05a59395dfa14e98c824b838b3e7ef9be056f21c482a9632f6401cfb50be699d podman-docker-5.8.2-4.el10_2.noarch.rpm SHA-256: f58363ca76057718b82d86bcdc9f0c895f64e62a5583e3a56aeb97c89e8deb39 podman-remote-5.8.2-4.el10_2.s390x.rpm SHA-256: 22fe1323f50db806965357bc07ea6e7a2560ac096e53b29f35a7d9bd35d590e7 podman-remote-debuginfo-5.8.2-4.el10_2.s390x.rpm SHA-256: e5ed0cd55cb2b63507e0a26f9cfaac4b3b4290e6106105a5de7078240c6a5344 podman-tests-debuginfo-5.8.2-4.el10_2.s390x.rpm SHA-256: 0444f27915bf76b50265bfe0b82a7fbdfea35b77a74f41d6a32861aec558b63f Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 SRPM podman-5.8.2-4.el10_2.src.rpm SHA-256: 974d01237064a9dbb91b2d62d58f02d2525953026b8ef032925c6cd78d4ede99 s390x podman-5.8.2-4.el10_2.s390x.rpm SHA-256: d5c6904b3fea73d89f3943c2a2f3421818aa0e2644fdff0d65d860f39772d54d podman-debuginfo-5.8.2-4.el10_2.s390x.rpm SHA-256: eafef23b74d765f3229553baf5661d3e025efb43e048d1ab49418aec73992a2c podman-debugsource-5.8.2-4.el10_2.s390x.rpm SHA-256: 05a59395dfa14e98c824b838b3e7ef9be056f21c482a9632f6401cfb50be699d podman-docker-5.8.2-4.el10_2.noarch.rpm SHA-256: f58363ca76057718b82d86bcdc9f0c895f64e62a5583e3a56aeb97c89e8deb39 podman-remote-5.8.2-4.el10_2.s390x.rpm SHA-256: 22fe1323f50db806965357bc07ea6e7a2560ac096e53b29f35a7d9bd35d590e7 podman-remote-debuginfo-5.8.2-4.el10_2.s390x.rpm SHA-256: e5ed0cd55cb2b63507e0a26f9cfaac4b3b4290e6106105a5de7078240c6a5344 podman-tests-debuginfo-5.8.2-4.el10_2.s390x.rpm SHA-256: 0444f27915bf76b50265bfe0b82a7fbdfea35b77a74f41d6a32861aec558b63f Red Hat Enterprise Linux for Power, little endian 10 SRPM podman-5.8.2-4.el10_2.src.rpm SHA-256: 974d01237064a9dbb91b2d62d58f02d2525953026b8ef032925c6cd78d4ede99 ppc64le podman-5.8.2-4.el10_2.ppc64le.rpm SHA-256: fd18109e1aff8ef37b9236b065fb2700e6859cba4f69706f1fb8abb27c05d465 podman-debuginfo-5.8.2-4.el10_2.ppc64le.rpm SHA-256: ddcf7aac