{"schema_version":"1.7.5","id":"SUSE-SU-2026:21291-1","published":"2026-04-23T12:23:33Z","modified":"2026-04-28T18:24:54.130331Z","related":["CVE-2025-31133","CVE-2025-47913","CVE-2025-47914","CVE-2025-52565","CVE-2025-52881"],"upstream":["CVE-2025-31133","CVE-2025-47913","CVE-2025-47914","CVE-2025-52565","CVE-2025-52881"],"summary":"Security update for podman","details":"This update for podman fixes the following issues:\n\n- CVE-2025-31133,CVE-2025-52565,CVE-2025-52881: Container breakouts by bypassing runc's restrictions for writing to arbitrary /proc files (bsc#1252376).\n- CVE-2025-47913: golang.org/x/crypto/ssh/agent: client process termination when receiving an unexpected message type in response to a key listing or signing request (bsc#1253542).\n- CVE-2025-47914: golang.org/x/crypto/ssh/agent: non validated message size can cause a panic due to an out of bounds read (bsc#1253993).\n","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-202621291-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1252376"},{"type":"REPORT","url":"https://bugzilla.suse.com/1253542"},{"type":"REPORT","url":"https://bugzilla.suse.com/1253993"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-31133"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-47913"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-47914"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-52565"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-52881"}]}