Fedora alert FEDORA-2026-d5c6299162 (podman-tui)
| From: | updates--- via package-announce <package-announce@lists.fedoraproject.org> | |
| To: | package-announce@lists.fedoraproject.org | |
| Subject: | [SECURITY] Fedora 44 Update: podman-tui-1.11.3-1.fc44 | |
| Date: | Tue, 07 Jul 2026 00:51:21 +0000 | |
| Message-ID: | <20260707005121.B4DC2796A7@bastion01.rdu3.fedoraproject.org> | |
| Archive-link: | Article |
-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-d5c6299162 2026-07-07 00:48:39.633185+00:00 -------------------------------------------------------------------------------- Name : podman-tui Product : Fedora 44 Version : 1.11.3 Release : 1.fc44 URL : https://github.com/containers/podman-tui Summary : Podman Terminal User Interface Description : podman-tui is a terminal user interface for Podman. podman-tui is using podman.socket service to communicate with podman environment and SSH to connect to remote podman machines. -------------------------------------------------------------------------------- Update Information: release 1.11.3 -------------------------------------------------------------------------------- ChangeLog: * Sun Jun 28 2026 Packit <hello@packit.dev> - 1.11.3-1 - Update to 1.11.3 upstream release -------------------------------------------------------------------------------- References: [ 1 ] Bug #2421877 - CVE-2025-66506 podman-tui: Fulcio: Denial of Service via crafted OpenID Connect (OIDC) token [epel-10] https://bugzilla.redhat.com/show_bug.cgi?id=2421877 [ 2 ] Bug #2421882 - CVE-2025-66506 podman-tui: Fulcio: Denial of Service via crafted OpenID Connect (OIDC) token [epel-9] https://bugzilla.redhat.com/show_bug.cgi?id=2421882 [ 3 ] Bug #2455640 - CVE-2026-34986 podman-tui: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2455640 [ 4 ] Bug #2455670 - CVE-2026-34986 podman-tui: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2455670 [ 5 ] Bug #2486211 - CVE-2026-45287 podman-tui: OpenTelemetry-Go: Denial of Service due to file descriptor leak [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2486211 [ 6 ] Bug #2486257 - CVE-2026-45287 podman-tui: OpenTelemetry-Go: Denial of Service due to file descriptor leak [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2486257 [ 7 ] Bug #2489878 - CVE-2026-39828 podman-tui: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2489878 [ 8 ] Bug #2489916 - CVE-2026-39828 podman-tui: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2489916 [ 9 ] Bug #2490044 - CVE-2026-39829 podman-tui: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2490044 [ 10 ] Bug #2490103 - CVE-2026-39829 podman-tui: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2490103 [ 11 ] Bug #2490437 - CVE-2026-39830 podman-tui: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2490437 [ 12 ] Bug #2490489 - CVE-2026-39830 podman-tui: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2490489 [ 13 ] Bug #2493062 - CVE-2026-39832 podman-tui: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2493062 [ 14 ] Bug #2493084 - CVE-2026-39832 podman-tui: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2493084 [ 15 ] Bug #2493481 - CVE-2026-39835 podman-tui: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2493481 [ 16 ] Bug #2493539 - CVE-2026-39835 podman-tui: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2493539 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-d5c6299162' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgr... All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- package-announce@lists.fedoraproject.org To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-cond... List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/package-ann... Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
