{"schema_version":"1.7.5","id":"SUSE-SU-2025:20279-1","published":"2025-04-22T13:50:31Z","modified":"2026-03-23T04:47:11.871842Z","related":["CVE-2023-45288","CVE-2024-11218","CVE-2024-1753","CVE-2024-3727","CVE-2024-9407","CVE-2025-22869","CVE-2025-27144"],"upstream":["CVE-2023-45288","CVE-2024-11218","CVE-2024-1753","CVE-2024-3727","CVE-2024-9407","CVE-2025-22869","CVE-2025-27144"],"summary":"Security update for podman","details":"This update for podman fixes the following issues:\n\n- CVE-2023-45288: Fixed closing connection when receiving too many headers (bsc#1236507).\n- CVE-2024-11218: Fixed container breakout by using --jobs=2 and a race condition when building a malicious Containerfile (bsc#1236270).\n- CVE-2025-22869: Fixed Denial of Service in the Key Exchange of golang.org/x/crypto/ssh (bsc#1239330).\n- CVE-2025-27144: Fixed Go JOSE's Parsing Vulnerable to Denial of Service (bsc#1237641).\n- CVE-2024-9407: Fixed Improper Input Validation in bind-propagation Option of Dockerfile RUN --mount Instruction (bsc#1231208).\n- CVE-2024-3727: Fixed digest type (bsc#1224112).\n- CVE-2024-1753: Fixed full container escape at build time (bsc#1221677). \n\nOther fixes:\n- Updated to version 5.2.5:\n  * RPM: remove dup Provides\n  * Packit: constrain koji and bodhi jobs to fedora package to avoid dupes\n  * Validate the bind-propagation option to `--mount`\n  * Updated Buildah to v1.37.4\n  * vendor: updated c/common to v0.60.4\n  * pkg/specgen: allow pasta when running inside userns\n  * libpod: convert owner IDs only with :idmap\n  * allow exposed sctp ports\n  * libpod: setupNetNS() correctly mount netns\n  * vendor: updated c/common to v0.60.3\n  * [skip-ci] Packit: split out ELN jobs and reuse fedora downstream targets\n  * [skip-ci] Packit: Enable sidetags for bodhi updates\n  * Updated gvisor-tap-vsock to 0.7.5\n  * CI: podman-machine: do not use cache registry\n  * [CI:DOCS] Add v5.2.2 lib updates to RELEASE_NOTES.md\n  * Update RELEASE_NOTES for v5.2.2\n  * [v5.2] Bump Buildah to v1.37.2, c/common v0.60.2, c/image v5.32.2\n  * [v5.2] golangci-lint: make darwin linting happy\n  * [v5.2] golangci-lint: make windows linting happy\n  * [v5.2] test/e2e: remove kernel version check\n  * [v5.2] golangci-lint: remove most skip dirs\n  * [v5.2] set !remote build tags where needed\n  * [v5.2] update golangci-lint to 1.60.1\n  * Packit: update targets for propose-downstream\n  * Create volume path before state initialization\n  * Update Cirrus DEST_BRANCH\n  * Bump to v5.2.2-dev\n  * Bump to v5.2.1\n  * Update release notes for v5.2.1\n  * [v5.2] Add zstd:chunked test fix\n  * [v5.2] Bump Buildah to v1.37.1, c/common v0.60.1, c/image v5.32.1\n  * libpod: reset state error on init\n  * libpod: do not save expected stop errors in ctr state\n  * libpod: fix broken saveContainerError()\n  * Bump to v5.2.1-dev\n  * Bump to v5.2.0\n  * Never skip checkout step in release workflow\n  * Bump to v5.2.0-dev\n  * Bump to v5.2.0-rc3\n  * Update release notes for v5.2.0-rc3\n  * Tweak versions in register_images.go\n  * fix network cleanup flake in play kube\n  * WIP: Fixes for vendoring Buildah\n  * Add --compat-volumes option to build and farm build\n  * Bump Buildah, c/storage, c/image, c/common\n  * libpod: bind ports before network setup\n  * pkg/api: do not leak config pointers into specgen\n  * build: Update gvisor-tap-vsock to 0.7.4\n  * test/system: fix borken pasta interface name checks\n  * test/system: fix bridge host.containers.internal test\n  * CI: system tests: instrument to allow failure analysis\n  * Use uploaded .zip for Windows action\n  * RPM: podman-iptables.conf only on Fedora\n  * Bump to v5.2.0-dev\n  * Bump to v5.2.0-rc2\n  * Update release notes for v5.2.0-rc2\n  * test/e2e: fix ncat tests\n  * libpod: add hidden env to set sqlite timeout\n  * Add support for StopSignal in quadlet .container files\n  * podman pod stats: fix race when ctr process exits\n  * Update module github.com/vbauerster/mpb/v8 to v8.7.4\n  * libpod: correctly capture healthcheck output\n  * Bump bundled krunkit to 0.1.2\n  * podman stats: fix race when ctr process exists\n  * nc -p considered harmful\n  * podman pod stats: fix pod rm race\n  * podman ps: fix racy pod name query\n  * system connection remove: use Args function to validate\n  * pkg/machine/compression: skip decompress bar for empty file\n  * nc -p considered harmful\n  * podman system df: fix fix ErrNoSuchCtr/Volume race\n  * podman auto-update: fix ErrNoSuchCtr race\n  * Fix name for builder in farm connection\n  * 700-play.bats: use unique pod/container/image/volume names\n  * safename: consistent within same test, and, dashes\n  * 700-kube.bats: refactor $PODMAN_TMPDIR/test.yaml\n  * 700-play.bats: eliminate $testYaml\n  * 700-play.bats: refactor clumsy yamlfile creation\n  * 700-play.bats: move _write_test_yaml up near top\n  * chore(deps): update dependency setuptools to v71\n  * Expand drop-in search paths * top-level (pod.d) * truncated (unit-.container.d)\n  * Remove references and checks for --gpus\n  * Do not crash on invalid filters\n  * fix(deps): update module github.com/rootless-containers/rootlesskit/v2 to v2.2.0\n  * Bump to v5.2.0-dev\n  * Bump to v5.2.0-rc1\n  * Keep the volume-driver flag deprecated\n  * Vendor in latest containers(common, storage,image, buildah)\n  * System tests: safe container/image/volume/etc names\n  * Implement disable default mounts via command line\n  * test: drop unmount for overlay\n  * test: gracefully terminate server\n  * libpod: shutdown Stop waits for handlers completion\n  * libpod: cleanup store at shutdown\n  * Add NetworkAlias= support to quadlet\n  * cmd: call shutdown handler stop function\n  * fix race conditions in start/attach logic\n  * swagger: exlude new docker network types\n  * vendor: bump c/storage\n  * update to docker 27\n  * contrib: use a distinct --pull-option= for each flag\n  * Update warning message when using external compose provider\n  * Update module github.com/cyphar/filepath-securejoin to v0.3.0\n  * Ignore result of EvalSymlinks on ENOENT\n  * test/upgrade: fix tests when netavark uses nftables\n  * test/system: fix network reload test with nftables\n  * test/e2e: rework some --expose tests\n  * test: remove publish tests from e2e\n  * CI: test nftables driver on fedora\n  * CI: use local registry, part 3 of 3: for developers\n  * CI: use local registry, part 2 of 3: fix tests\n  * CI: use local registry, part 1 of 3: setup\n  * CI: test composefs on rawhide\n  * chore(deps): update module google.golang.org/grpc to v1.64.1 [security]\n  * chore(deps): update dependency setuptools to ~=70.3.0\n  *  Improve container filenname ambiguity.\n  * containers/attach: Note bug around goroutine leak\n  * Drop minikube CI test\n  * add libkrun test docs\n  * fix(deps): update module tags.cncf.io/container-device-interface to v0.8.0\n  * cirrus: check for header files in source code check\n  * pkg/machine/e2e: run debug command only for macos\n  * create runtime's worker queue before queuing any job\n  * test/system: fix pasta host.containers.internal test\n  * Visual Studio BuildTools as a MinGW alternative\n  * SetupRootless(): only reexec when needed\n  * pkg/rootless: simplify reexec for container code\n  * cirrus: add missing test/tools to danger files\n  * fix(deps): update module golang.org/x/tools to v0.23.0\n  * Windows Installer: switch to wix5\n  * fix(deps): update module golang.org/x/net to v0.27.0\n  * pkg/machine/e2e: print tests timings at the end\n  * pkg/machine/e2e: run debug commands after init\n  * pkg/machine/e2e: improve timeout handling\n  * libpod: first delete container then cidfile\n  * fix(deps): update module golang.org/x/term to v0.22.0\n  * System test fixes\n  * cirrus.yml: automatic skips based on source\n  * fix(deps): update module github.com/containers/ocicrypt to v1.2.0\n  * podman events: fix error race\n  * chore(deps): update dependency setuptools to ~=70.2.0\n  * fix(deps): update module github.com/gorilla/schema to v1.4.1 [security]\n  * Update CI VM images\n  * pkg/machine/e2e: fix broken cleanup\n  * pkg/machine/e2e: use tmp file for connections\n  * test/system: fix podman --image-volume to allow tmpfs storage\n  * CI: mount tmpfs for container storage\n  * docs: --network remove missing leading sentence\n  * specgen: parse devices even with privileged set\n  * vendor: update c/storage\n  * Remove the unused machine volume-driver\n  * feat(quadlet): log option handling\n  * Error when machine memory exceeds system memory\n  * machine: Always use --log-file with gvproxy\n  * CI: Build-Each-Commit test: run only on PRs\n  * Small fixes for testing libkrun\n  * Podman machine resets all providers\n  * Clearly indicate names w/ URLencoded duplicates\n  * [skip-ci] Packit: split rhel and centos-stream jobs\n  * apple virtiofs: fix racy mount setup\n  * cirrus: fix broken macos artifacts URL\n  * libpod/container_top_linux.c: fix missing header\n  * refactor(build): improve err when file specified by -f does not exist\n  * Minor: Remove unhelpful comment\n  * Update module github.com/openshift/imagebuilder to v1.2.11\n  * Minor: Rename the OSX Cross task\n  * [skip-ci] Remove conditionals from changelog\n  * podman top: join the container userns\n  * Run linting in parallel with building\n  * Fix missing Makefile target dependency\n  * build API: accept platform comma separated\n  * [skip-ci] RPM: create podman-machine subpackage\n  * ExitWithError() - more upgrades from Exit()\n  * test/e2e: remove podman system service tests\n  * cirrus: reduce int tests timeout\n  * cirrus: remove redundant skip logic\n  * pkg/machine/apple: machine stop timeout\n  * CI: logformatter: link to correct PR base\n  * Update module github.com/crc-org/crc/v2 to v2.38.0\n  * ExitWithError(): continued\n  * test/system: Add test steps for journald log check in quadlet\n  * restore: fix missing network setup\n  * podman run use pod userns even with --pod-id-file\n  * macos-installer: bundle krunkit\n  * remote API: fix pod top error reporting\n  * libpod API: return proper error status code for pod start\n  * fix #22233\n  * added check for `registry.IsRemote()`. and correct error message.\n  * fix #20686\n  * pkg/machine/e2e: Remove unnecessary copy of machine image.\n  * libpod: intermediate mount if UID not mapped into the userns\n  * libpod: avoid chowning the rundir to root in the userns\n  * libpod: do not chmod bind mounts\n  * libpod: unlock the thread if possible\n  * CI Cleanup: Remove cgroups v1 support\n  * ExitWithError() - more upgrades from Exit()\n  * remote: fix incorrect CONTAINER_CONNECTION parsing\n  * container: pass KillSignal and StopTimeout to the systemd scope\n  * libpod: fix comment\n  * e2e: test container restore in pod by name\n  * docs: Adds all PushImage supported paramters to openapi docs.\n  * systests: kube: bump up a timeout\n  * cirrus.yml: add CI:ALL mode to force all tests\n  * cirrus.yml: implement skips based on source changes\n  * CI VMs: bump\n  * restore: fix container restore into pod\n  * sqlite_state: Fix RewriteVolumeConfig\n  * chore(deps): update dependency setuptools to ~=70.1.0\n  * Quadlet - use specifier for unescaped values for templated container name\n  * cirrus: check for system test leaks in nightly\n  * test/system: check for leaks in teardown suite\n  * test/system: speed up basic_{setup,teardown}()\n  * test/system: fix up many tests that do not cleanup\n  * test/system: fix podman --authfile=nonexistent-path\n  * Update module github.com/containernetworking/plugins to v1.5.1\n  * Update module github.com/checkpoint-restore/checkpointctl to v1.2.1\n  * Update module github.com/spf13/cobra to v1.8.1\n  * Update module github.com/gorilla/schema to v1.4.0\n  * pkg/machine/wsl: force terminate wsl instance\n  * pkg/machine/wsl: wrap command errors\n  * [CI:DOCS] Quadlet - add note about relative path resolution\n  * CI: do not install python packages at runtime\n  * Release workflow: Include candidate descriptor\n  * Minor: Fix indentation in GHA release workflow\n  * GHA: Send release notification mail\n  * GHA: Validate release version number\n  * Remove references to --pull=true and --pull=false\n  * ExitWithError, continued\n  * podman: add new hidden flag --pull-option\n  * [CI:DOCS] Fix typos in podman-build\n  * infra: mark storageSet when imagestore is changed\n  * [CI:DOCS] Add jnovy as reviewer and approver\n  * fix(deps): update module google.golang.org/protobuf to v1.34.2\n  * refactor(machine,wsl): improve operations of Windows API\n  * --squash --layers=false should be allowed\n  * fix(deps): update module github.com/checkpoint-restore/checkpointctl to v1.2.0\n  * update golangci-lint to v1.59.1\n  * Rename master to main in CONTRIBUTING.md\n  * podman 5, pasta and inter-container networking\n  * libpod: do not resuse networking on start\n  * machine/linux: Switch to virtiofs by default\n  * machine/linux: Support virtiofs mounts (retain 9p default)\n  * machine/linux: Use memory-backend-memfd by default\n  * ExitWithError() - continued\n  * Enable libkrun provider to open a debug console\n  * Add new targets on Windows makefile (winmake.ps1)\n  * fix(deps): update module github.com/docker/docker to v26.1.4+incompatible\n  * fix(deps): update module github.com/crc-org/crc/v2 to v2.37.1\n  * fix(deps): update module golang.org/x/tools to v0.22.0\n  * fix(deps): update module golang.org/x/net to v0.26.0\n  * libpod: fix 'podman kube generate' on FreeBSD\n  * fix(deps): update module golang.org/x/sys to v0.21.0\n  * libpod: do not leak systemd hc startup unit timer\n  * vendor latest c/common\n  * pkg/rootless: set _CONTAINERS_USERNS_CONFIGURED correctly\n  * run bats -T, to profile timing hogs\n  * test/system: speed up podman ps --external\n  * test/system: speed up podman network connect/disconnect\n  * test/system: speed up podman network reload\n  * test/system: speed up quadlet - pod simple\n  * test/system: speed up podman parallel build should not race\n  * test/system: speed up podman cp dir from host to container\n  * test/system: speed up podman build - workdir, cmd, env, label\n  * test/system: speed up podman --log-level recognizes log levels\n  * test/system: remove obsolete debug in net connect/disconnect test\n  * test/system: speed up quadlet - basic\n  * test/system: speed up user namespace preserved root ownership\n  * System tests: add `podman system check` tests\n  * Add `podman system check` for checking storage consistency\n  * fix(deps): update module github.com/crc-org/crc/v2 to v2.37.0\n  * fix(libpod): add newline character to the end of container's hostname file\n  * fix(deps): update module github.com/openshift/imagebuilder to v1.2.10\n  * fix(deps): update github.com/containers/image/v5 digest to aa93504\n  * Fix 5.1 release note re: runlabel\n  * test/e2e: use local skopeo not image\n  * fix(deps): update golang.org/x/exp digest to fd00a4e\n  * [CI:DOCS] Add contrib/podmanimage/stable path back in repo\n  * chore(deps): update dependency requests to ~=2.32.3\n  * fix(deps): update github.com/containers/image/v5 digest to 2343e81\n  * libpod: do not move podman with --cgroups=disabled\n  * Update release notes on Main to v5.1.0\n  * test: look at the file base name\n  * tests: simplify expected output\n  * Sigh, new VMs again\n  * Fail earlier when no containers exist in stats\n  * Add Hyper-V option in windows installer\n  * libpod: cleanup default cache on system reset\n  * vendor: update c/image\n  * test/system: speed up kube generate tmpfs on /tmp\n  * test/system: speed up podman kube play tests\n  * test/system: speed up podman shell completion test\n  * test/system: simplify test signal handling in containers\n  * test/system: speed up podman container rm ...\n  * test/system: speed up podman ps - basic tests\n  * test/system: speed up read-only from containers.conf\n  * test/system: speed up podman logs - multi ...\n  * test/system: speed up podman run --name\n  * Debian: switch to crun\n  * test/system: speed up podman generate systemd - envar\n  * test/system: speed up podman-kube@.service template\n  * test/system: speed up kube play healthcheck initialDelaySeconds\n  * test/system: speed up exit-code propagation test\n  * test/system: speed up \"podman run --timeout\"\n  * test/system: fix slow kube play --wait with siginterrupt\n  * undo auto-formatting\n  * test/system: speed up podman events tests\n  * Quadlet: Add support for .build files\n  * test/system: speed up \"podman auto-update using systemd\"\n  * test/system: remove podman wait test\n  * tests: disable tests affected by a race condition\n  * update golangci-lint to v1.59.0\n  * kubernetes_support.md: Mark volumeMounts.subPath as supported\n  * working name of pod on start and stop\n  * fix(deps): update module github.com/onsi/ginkgo/v2 to v2.19.0\n  * Bump Buildah to v1.36.0\n  * fix(deps): update module github.com/burntsushi/toml to v1.4.0\n  * fix typo in Tutorials.rst\n  * Mac PM test: Require pre-installed rosetta\n  * test/e2e: fix new error message\n  * Add configuration for podmansh\n  * Update containers/common to latest main\n  * Only stop chowning volumes once they're not empty\n  * podman: fix --sdnotify=healthy with --rm\n  * libpod: wait another interval for healthcheck\n  * quadlet: Add a network requirement on .image units\n  * test, pasta: Ignore deprecated addresses in tests\n  * [CI:DOCS] performance: update network docs\n  * fix(deps): update module github.com/onsi/ginkgo/v2 to v2.18.0\n  * CI: disable minikube task\n  * [CI:DOCS] Fix windows action trigger\n  * chore(deps): update dependency setuptools to v70\n  * Check AppleHypervisor before accessing it\n  * fix(deps): update module github.com/containernetworking/plugins to v1.5.0\n  * [CI:DOCS] Update dependency golangci/golangci-lint to v1.58.2\n  * add podman-clean-transient.service service to rootless\n  * [CI:DOCS] Update podman network docs\n  * fix incorrect host.containers.internal entry for rootless bridge mode\n  * vendor latest c/common main\n  * Add Rosetta support for Apple Silicon mac\n  * bump main to 5.2.0-dev\n  * Use a defined constant instead of a hard-coded magic value\n  * cirrus: use faster VM's for integration tests\n  * fix(deps): update github.com/containers/gvisor-tap-vsock digest to 01a1a0c\n  * [CI:DOCS] Fix Mac pkg link\n  * test: remove test_podman* scripts\n  * test/system: fix documentation\n  * Return StatusNotFound when multiple volumes matching occurs\n  * container_api: do not wait for healtchecks if stopped\n  * libpod: wait for healthy on main thread\n  * `podman events`: check for an error after we finish reading events\n  * remote API: restore v4 payload in container inspect\n  * Fix updating connection when SSH port conflict happens\n  * rootless: fix reexec to use /proc/self/exe\n  * ExitWithError() - enforce required exit status & stderr\n  * ExitWithError() - a few that I missed\n  * [skip-ci] Packit: use only one value for `packages` key for `trigger: commit` copr builds\n  * Revert \"Temporarily disable rootless debian e2e testing\"\n  * CI tests: enforce TMPDIR on tmpfs\n  * use new CI images with tmpfs /tmp\n  * run e2e test on tmpfs\n  * Update module github.com/crc-org/crc/v2 to v2.36.0\n  * [CI:DOCS] Use checkout@v4 in GH Actions\n  * ExitWithError() - rmi_test\n  * ExitWithError() - more r files\n  * ExitWithError() - s files\n  * ExitWithError() - more run_xxx tests\n  * Fix podman-remote support for `podman farm build`\n  * [CI:DOCS] Trigger windows installer action properly\n  * Revert \"container stop: kill conmon\"\n  * Ensure that containers do not get stuck in stopping\n  * [CI:DOCS] Improvements to make validatepr\n  * ExitWithError() - rest of the p files\n  * [CI:DOCS] Update dependency golangci/golangci-lint to v1.58.1\n  * Graceful shutdown during podman kube down\n  * Remove duplicate  call\n  * test/system: fix broken \"podman volume globs\" test\n  * Quadlet/Container: Add GroupAdd option\n  * Don't panic if a runtime was configured without paths\n  * update c/{buildah,common,image,storage} to latest main\n  * update golangci-lint to 1.58\n  * machine: Add LibKrun provider detection\n  * ExitWithError() - continue tightening\n  * fix(deps): update module google.golang.org/protobuf to v1.34.1\n  * test: improve test for powercap presence\n  * fix(deps): update module github.com/onsi/ginkgo/v2 to v2.17.3\n  * fix(deps): update module go.etcd.io/bbolt to v1.3.10\n  * fix(deps): update module golang.org/x/tools to v0.21.0\n  * [skip-ci] RPM: `bats` required only on Fedora\n  * fix(deps): update module golang.org/x/exp to v0.0.0-20240506185415-9bf2ced13842\n  * gpdate and remove parameter settings in `.golangci.yml`\n  * ExitWithError() - play_kube_test.go\n  * Temporarily disable rootless debian e2e testing\n  * fix(deps): update module golang.org/x/crypto to v0.23.0\n  * CI Docs: Clarify passthrough_envars() comments\n  * Skip machine tests if they don't need to be run\n  * Update CI VMs to F40, F39, D13\n  * ExitWithError() - v files\n  * Update module golang.org/x/term to v0.20.0\n  * machine: Add provider detection API\n  * util: specify a not empty pause dir for root too\n  * Add missing option 'healthy' to output of `podman run --help`\n  * [CI:DOCS] Add info on the quay.io images to the README.md\n  * Add a random suffix to healthcheck unit names\n  * test/e2e: remove toolbox image\n  * Also substitute $HOME in runlabel with user's homedir\n  * Update module github.com/cyphar/filepath-securejoin to v0.2.5\n  * Change tmpDir for macOS\n  * ExitWithError() - pod_xxx tests\n  * ExitWithError() -- run_test.go\n  * Update module golang.org/x/exp to v0.0.0-20240416160154-fe59bbe5cc7f\n  * Update module github.com/shirou/gopsutil/v3 to v3.24.4\n  * Update module github.com/docker/docker to v26.1.1+incompatible\n  * GHA: Attempt fix exceeded a secondary rate limit\n  * vendor ginkgo 2.17.2 into test/tools\n  * Fix machine volumes with long path and paths with dashes\n  * Update module google.golang.org/protobuf to v1.34.0\n  * Update module github.com/crc-org/crc/v2 to v2.35.0\n  * Update module github.com/onsi/gomega to v1.33.1\n  * test/e2e: podman unshare image mount fix tmpdir leak\n  * test/e2e: do not leak /tmp/private_file\n  * test/e2e: \"persistentVolumeClaim with source\" do not leak file\n  * e2e tests: use /var/tmp, not $TMPDIR, as workdirs\n  * Update dependency pytest to v8.1.2\n  * Remove unncessary lines at the end of specfile summary\n  * Clean machine pull cache\n  * Add krun support to podman machine\n  * Use custom image for make validatepr\n  * test/e2e: force systemd cgroup manager\n  * e2e and bindings tests: fix $PATH setup\n  * Makefile: remove useless HACK variable in e2e test\n  * test/e2e: fix volumes and suid/dev/exec options\n  * test/e2e: volumes and suid/dev/exec options works remote\n  * test/e2e: fix limits test\n  * Update module github.com/rootless-containers/rootlesskit/v2 to v2.1.0\n  * Correct option name `ip` -> `ip6`\n  * Add the ability to automount images as volumes via play\n  * Add support for image volume subpaths\n  * Bump Buildah to latest main\n  * Update Makefile to Go 1.22 for in-container\n  * ExitWithError() - yet more low-hanging fruit\n  * ExitWithError() - more low-hanging fruit\n  * ExitWithError() - low-hanging fruit\n  * chore: fix function names in comment\n  * Remove redundant Prerequisite before build section\n  * Remove PKG_CONFIG_PATH\n  * Add installation instructions for openSUSE\n  * Replace golang.org/x/exp/slices with slices from std\n  * Update to go 1.21\n  * fix(deps): update module github.com/docker/docker to v26.1.0+incompatible\n  * [CI:DOCS] Fix artifact action\n  * [skip-ci] Packit/rpm: remove el8 jobs and spec conditionals\n  * e2e tests: stop littering\n  * [CI:DOCS] format podman-pull example as code\n  * [CI:DOCS] Build & upload release artifacts with GitHub Actions\n  * libpod: getHealthCheckLog() remove unessesary check\n  * add containers.conf healthcheck_events support\n  * vendor latest c/common\n  * libpod: make healthcheck events more efficient\n  * libpod: wrap store setup error message\n  * [skip-ci] Packit: enable CentOS 10 Stream build jobs\n  * pkg/systemd: use fileutils.(Le|E)xists\n  * pkg/bindings: use fileutils.(Le|E)xists\n  * pkg/util: use fileutils.(Le|E)xists\n  * pkg/trust: use fileutils.(Le|E)xists\n  * pkg/specgen: use fileutils.(Le|E)xists\n  * pkg/rootless: use fileutils.(Le|E)xists\n  * pkg/machine: use fileutils.(Le|E)xists\n  * pkg/domain: use fileutils.(Le|E)xists\n  * pkg/api: use fileutils.(Le|E)xists\n  * libpod: use fileutils.(Le|E)xists\n  * cmd: use fileutils.(Le|E)xists\n  * vendor: update containers/{buildah,common,image,storage}\n  * fix(deps): update module github.com/docker/docker to v26.0.2+incompatible [security]\n  * fix podman-pod-restart.1.md typo\n  * [skip-ci] Packit: switch to EPEL instead of centos-stream+epel-next\n  * fix(deps): update module github.com/onsi/gomega to v1.33.0\n  * Add more annnotation information to podman kupe play man page\n  * test/compose: remove compose v1 code\n  * CI: remove compose v1 tests\n  * fix: close resource file\n  * [CI:DOCS] Fix windows installer action\n  * fix(deps): update module tags.cncf.io/container-device-interface to v0.7.2\n  * add `list` as an alias to list networks\n  * Add support for updating restart policy\n  * Add Compat API for Update\n  * Make `podman update` changes persistent\n  * Emergency fix (well, skip) for failing bud tests\n  * fix swagger doc for manifest create\n  * [CI:DOCS] options/network: fix markdown lists\n  * Makefile: do not hardcode `GOOS` in `podman-remote-static` target\n  * chore(deps): update module golang.org/x/crypto to v0.17.0 [security]\n  * chore(deps): update dependency setuptools to ~=69.5.0\n  * Fix some comments\n  * swagger fix infinitive recursion on some types\n  * install swagger from source\n  * Revert \"Swap out javascript engine\"\n  * podman exec CID without command should exit 125\n  * (minor) prefetch systemd image before use\n  * Update go-swagger version\n  * Swap out javascript engine\n  * fix(deps): update module github.com/docker/docker to v26.0.1+incompatible\n  * Add os, arch, and ismanifest to libpod image list\n  * [CI:DOCS]Initial PR validation\n  * fix(deps): update github.com/containers/gvisor-tap-vsock digest to d744d71\n  * vendor ginkgo 2.17.1 into test/tools\n  * fix \"concurrent map writes\" in network ls compat endpoint\n  * chore(deps): update dependency pytest to v8\n  * e2e: redefine ExitWithError() to require exit code\n  * docs: fix missleading run/create --expose description\n  * podman ps: show exposed ports under PORTS as well\n  * rootless: drop function ReadMappingsProc\n  * fix(deps): update module github.com/vbauerster/mpb/v8 to v8.7.3\n  * New CI VMs, to give us pasta 2024-04-05\n  * Add big warning to GHA workflow\n  * GHA: Fix intermittent workflow error\n  * fix(deps): update module golang.org/x/tools to v0.20.0\n  * e2e tests: remove requirement for fuse-overlayfs\n  * docs: update Quadlet volume Options desc\n  * fix(deps): update module golang.org/x/sync to v0.7.0\n  * Fix relabeling failures with Z/z volumes on Mac\n  * fix(deps): update module golang.org/x/net to v0.24.0\n  * Makefile: fix annoying errors in docs generation\n  * chore: fix function names in comment\n  * Bump tags.cncf.io/container-device-interface to v0.7.1\n  * fix(deps): update module golang.org/x/crypto to v0.22.0\n  * Detect unhandled reboots and require user intervention\n  * podman --runroot: remove 50 char length restriction\n  * update github.com/rootless-containers/rootlesskit to v2\n  * Update module github.com/gorilla/schema to v1.3.0\n  * Update dependency requests-mock to ~=1.12.1\n  * Update module github.com/crc-org/crc/v2 to v2.34.1\n  * rm --force work for more than one arg\n  * [CI:DOCS] Update kube docs\n  * fix(deps): update module github.com/shirou/gopsutil/v3 to v3.24.3\n  * [CI:DOCS] Add GitHub action to update version on Podman.io\n  * [CI:DOCS] Update dependency golangci/golangci-lint to v1.57.2\n  * Windows: clean up temporary perl install\n  * pkg/util: FindDeviceNodes() ignore ENOENT errors\n  * [CI:DOCS] build deps: make-validate needs docs\n  * test/system: add rootless-netns test for setup errors\n  * vendor latest c/common main\n  * container: do not chown to dest target with U\n  * [CI:DOCS] golangci-lint: update deprecated flags\n  * systests: conditionalize slirp4netns tests\n  * CI: systests: instrument flaky tests\n  * s3fs docs\n  * test: do not skip tests under rootless\n  * Add note about host networking to Kube PublishPort option\n  * Inject additional build tags from the environment\n  * libpod: use original IDs if idmap is provided\n  * Switch back to checking out the same branch the action script runs in\n  * docs/podman-login: Give an example of writing the persistent path\n  * CI: Bump VMs to 2024-03-28\n  * [skip-ci] Update dawidd6/action-send-mail action to v3.12.0\n  * fix(deps): update module github.com/openshift/imagebuilder to v1.2.7\n  * Fix reference to deprecated types.Info\n  * Use logformatter for podman_machine_windows_task\n  * applehv: Print vfkit logs in --log-level debug\n  * [CI:DOCS]Add Mario to reviewers list\n  * [CI:DOCS] Document CI-maintenance job addition\n  * Add golang 1.21 update warning\n  * Add rootless network command to `podman info`\n  * libpod: don't warn about cgroupsv1 on FreeBSD\n  * hyperv: error if not admin\n  * Properly parse stderr when updating container status\n  * [skip-ci] Packit: specify fedora-latest in propose-downstream\n  * Use built-in ssh impl for all non-pty operations\n  * Add support for annotations\n  * hyperv: fix machine rm -r\n  * [skip-ci] Packit: Enable CentOS Stream 10 update job\n  * 5.0 release note fix typo in cgroupv1 env var\n  * fix remote build isolation on client side\n  * chore: remove repetitive words\n  * Dont save remote context in temp file but stream and extract\n  * fix remote build isolation when server runs as root\n  * util: use private propagation with bind\n  * util: add some tests for ProcessOptions\n  * util: refactor ProcessOptions into an internal function\n  * util: rename files to snake case\n  * Add LoongArch support for libpod\n  * fix(deps): update github.com/containers/common digest to bc5f97c\n  * [CI:DOCS] Update dependency golangci/golangci-lint to v1.57.1\n  * fix(deps): update module github.com/docker/docker to v25.0.5+incompatible [security]\n  * fix(deps): update module github.com/onsi/gomega to v1.32.0\n  * [CI:DOCS] Update dependency golangci/golangci-lint to v1.57.0\n  * Update module github.com/cpuguy83/go-md2man/v2 to v2.0.4\n  * Fix type-o\n  * Use correct extension in suite\n  * minikube: instrument tests, to allow debugging failures\n  * libpod: restart always reconfigure the netns\n  * use new c/common pasta2 setup logic to fix dns\n  * utils: drop conversion float->string->float\n  * utils: do not generate duplicate range\n  * logformatter: handle Windows logs\n  * utils: add test for the new function\n  * utils: move rootless code to a new function\n  * xref-helpmsgs-manpages: cross-check Commands.rst\n  * test/system: Add support for multipath routes in pasta networking tests\n  * [skip-ci] rpm: use macro supported vendoring\n  * Adjust to the standard location of gvforwarder used in new images\n  * Makefile: add target `podman-remote-static`\n  * Switch to 5.x WSL machine os stream using new automation\n  * Cleanup build scratch dir if remote end disconnects while passing the context\n  * bump main to 5.1.0-dev\n  * Use faster gzip for compression for 3x speedup for sending large contexts to remote\n  * pkg/machine: make checkExclusiveActiveVM race free\n  * pkg/machine/wsl: remove unused CheckExclusiveActiveVM()\n  * pkg/machine: CheckExclusiveActiveVM should also check for starting\n  * pkg/machine: refresh config after we hold lock\n  * Update dependency setuptools to ~=69.2.0\n  * [skip-ci] rpm: update containers-common dep on f40+\n  * fix invalid HTTP header values when hijacking a connection\n  * Add doc to build podman on windows without MSYS\n  * Removing CRI-O related annotations\n  * fix(deps): update module github.com/containers/ocicrypt to v1.1.10\n  * Pass the restart policy to the individual containers\n  * kube play: always pull when both imagePullPolicy and tag are missing\n\n","affected":[{"package":{"name":"podman","ecosystem":"SUSE:Linux Micro 6.1","purl":"pkg:rpm/suse/podman&distro=SUSE%20Linux%20Micro%206.1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.2.5-slfo.1.1_1.1"}]}],"ecosystem_specific":{"binaries":[{"podman":"5.2.5-slfo.1.1_1.1","podman-docker":"5.2.5-slfo.1.1_1.1","podman-remote":"5.2.5-slfo.1.1_1.1","podmansh":"5.2.5-slfo.1.1_1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2025:20279-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2025/suse-su-202520279-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1221677"},{"type":"REPORT","url":"https://bugzilla.suse.com/1224112"},{"type":"REPORT","url":"https://bugzilla.suse.com/1231208"},{"type":"REPORT","url":"https://bugzilla.suse.com/1236270"},{"type":"REPORT","url":"https://bugzilla.suse.com/1236507"},{"type":"REPORT","url":"https://bugzilla.suse.com/1237641"},{"type":"REPORT","url":"https://bugzilla.suse.com/1239330"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-45288"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-11218"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-1753"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-3727"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-9407"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-22869"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-27144"}]}