Bug 2495095 - CVE-2026-57231 podman: Podman: Information disclosure via malicious container image environment variables [fedora-all]
Summary: CVE-2026-57231 podman: Podman: Information disclosure via malicious container...
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: None
Product: Fedora
Classification: Fedora
Component: podman
Version: rawhide
Hardware: Unspecified
OS: Unspecified
high
high
Target Milestone: ---
Assignee: Lokesh Mandvekar
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard: {"flaws": ["302c10e4-22d9-4a20-a35b-5...
Depends On:
Blocks: CVE-2026-57231
TreeView+ depends on / blocked
 
Reported: 2026-06-30 18:43 UTC by Jon Moroney
Modified: 2026-09-23 03:19 UTC (History)
12 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2026-07-10 14:30:04 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Jon Moroney 2026-06-30 18:43:16 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

Podman is a tool for managing OCI containers and pods. From 1.8.1 until 5.8.4, a container image that contains a environment variable with just a key and no value can trick podman into passing that variable from the host into the container. This is made worse by the fact that using an asterisk (*) will cause podman to pass all host variables into the container. So essentially a malicious image can exfiltrate all podman environment variables that are set in the session from where the container is launched. This vulnerability is fixed in 5.8.4 and 6.0.0.

Comment 1 Lokesh Mandvekar 2026-07-10 14:30:04 UTC
v5.8.4 is in Fedora


Note You need to log in before you can comment on or make changes to this bug.