Your message dated Wed, 19 Aug 2026 12:49:05 +0000
with message-id <[email protected]>
and subject line Bug#1141502: fixed in podman 5.8.4+ds1-1
has caused the Debian Bug report #1141502,
regarding podman: CVE-2026-57231
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1141502: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1141502
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: podman
Version: 5.8.3+ds1-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi,
The following vulnerability was published for podman.
CVE-2026-57231[0]:
| Podman is a tool for managing OCI containers and pods. From 1.8.1
| until 5.8.4, a container image that contains a environment variable
| with just a key and no value can trick podman into passing that
| variable from the host into the container. This is made worse by the
| fact that using an asterisk (*) will cause podman to pass all host
| variables into the container. So essentially a malicious image can
| exfiltrate all podman environment variables that are set in the
| session from where the container is launched. This vulnerability is
| fixed in 5.8.4 and 6.0.0.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-57231
https://www.cve.org/CVERecord?id=CVE-2026-57231
[1]
https://github.com/podman-container-tools/podman/security/advisories/GHSA-4hq8-gpf5-8p68
[2]
https://github.com/podman-container-tools/podman/commit/85832029d537c2c0df89e47d4a03d55ba099a848
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: podman
Source-Version: 5.8.4+ds1-1
Done: Reinhard Tartler <[email protected]>
We believe that the bug you reported is fixed in the latest version of
podman, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Reinhard Tartler <[email protected]> (supplier of updated podman package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Tue, 18 Aug 2026 08:37:22 -0400
Source: podman
Architecture: source
Version: 5.8.4+ds1-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Go Packaging Team
<[email protected]>
Changed-By: Reinhard Tartler <[email protected]>
Closes: 1141502
Changes:
podman (5.8.4+ds1-1) unstable; urgency=medium
.
* New upstream version, Closes: #1141502, Fixes: CVE-2026-57231
* Backport upstream patches to restore compatibility with
containers/storage v1.63
Checksums-Sha1:
65ef684823340e8a10a5e3ce854a61af0ba2b1b8 4968 podman_5.8.4+ds1-1.dsc
a3fc055cb4195a28b64dc13d4d16904d1227d798 3001916 podman_5.8.4+ds1.orig.tar.xz
c088ef5c4bf0cf70617206bdb5f90e59ae388a7b 30584 podman_5.8.4+ds1-1.debian.tar.xz
Checksums-Sha256:
66555e8562756c2b18386208ede71f2bdbad5f22420ded38e1158beb12ae5eca 4968
podman_5.8.4+ds1-1.dsc
b23586815f8f2c79e45a9446c381270068818a2e99f19585d27cf7b5718c24f2 3001916
podman_5.8.4+ds1.orig.tar.xz
46129b15d4c6d42df5d59488731f6653fde0cbd400c4a1765a1d6c93cdc75433 30584
podman_5.8.4+ds1-1.debian.tar.xz
Files:
8106af4e505881750f34d98e472aaba8 4968 admin optional podman_5.8.4+ds1-1.dsc
e886039339668732f60b419459ab0bb5 3001916 admin optional
podman_5.8.4+ds1.orig.tar.xz
48ca6f4d76560a9648cca5262d42174a 30584 admin optional
podman_5.8.4+ds1-1.debian.tar.xz
-----BEGIN PGP SIGNATURE-----
iQJIBAEBCgAyFiEEMN59F2OrlFLH4IJQSadpd5QoJssFAmqFo+YUHHNpcmV0YXJ0
QHRhdXdhcmUuZGUACgkQSadpd5QoJsveBRAAvU4eL7t+/zAKbLUPtDnzGnrzaw9y
0f7FD2DC5skQaX1sgzsfjQl/aBTmNzXZ3jyMM7cgh7eco+azc74xf0BBdPMqS2sK
hsjKdu8yBL8lO0rg8gYYhQwTA6dR53xNYAQSGbuUas3e6tEkaOuxRKPy6ZUF4jYh
cJnKqQeuyiSsVh8wtZAIQbUb4ed3yZo+zj2gBRreLCuS0D5HjV5gBA2CVFs24Lpn
LxqPh2lbLZbp8Qx4PEY751EARNzvGxbJkM0HStsRcOymcpnUGsqLfaZGlbf1CndI
37SHhbshpCVdvtxOYf5bNXaGnY+8ZWPMTOW0arDc9ckN9ZqiOPnEVw5yBfXyDc/m
LAI4xYIgkjSoi4qH9JRqGX0Ycwip+M7Nt3ld3tLJS8psZl4F+fAYrPkN6F66oQoU
qgRWKiSP0WpMyE/OdkLr8pcyP74C5k+b9lbrEM623kSRTB05JI374WIXReWAbbQn
LZQvBrpQOmQe8XyHI7brGoPvcWFfxgu5uSmTsPpPWbXdDE2xz6E/myXlVNcGM0rD
u0Pg1AqnV6RQLVnQ3NwK+NDco/dS5jwYHjXx4FpPD+3AnAGGhIrXcp3/5nPZdlyo
YEvaZ6MIMxWSJjmiEWhRlx7MYo2Q8lJsrVngZz++FqbgwFgvnuvGfzDsp+OCPOgv
B8SheLx6uDwTL0k=
=YQHq
-----END PGP SIGNATURE-----
pgpzRF3oXTEOf.pgp
Description: PGP signature
--- End Message ---
_______________________________________________
Pkg-go-maintainers mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-go-maintainers