[CLSA-2026:1786960012] podman: Fix of CVE-2026-39835
Type:
security
Severity:
Important
Release date:
2026-08-17 09:47:02 UTC
Description:
- CVE-2026-39835: return an error instead of panicking when the vendored golang.org/x/crypto/ssh CertChecker IsHostAuthority or IsUserAuthority callbacks are nil, preventing a nil-pointer dereference DoS
CVEs fixed:
Updated packages:
  • podman-4.4.1-13.el9_2.tuxcare.els16.x86_64.rpm
    sha:323f07d047ddf6f5d853c4624581ec7ca4f62f420580463876616d03d2e179c3
  • podman-docker-4.4.1-13.el9_2.tuxcare.els16.noarch.rpm
    sha:47568b1d51d6cdbb40de49228894544c40a84edc98b50bb3497dd95acda904dc
  • podman-gvproxy-4.4.1-13.el9_2.tuxcare.els16.x86_64.rpm
    sha:a6490a1bd25f6fb32eb92f73af0fae2edd0d270990e86365b31f895e8027630e
  • podman-plugins-4.4.1-13.el9_2.tuxcare.els16.x86_64.rpm
    sha:f32cc7d3cfe49d5a51dd4b1a45a57a37cc1aa5fbd22174c79daa95831e28ecd2
  • podman-remote-4.4.1-13.el9_2.tuxcare.els16.x86_64.rpm
    sha:302974c4d156444d5177090fb37274f397c03979a59f86a6014a5a8b95b8f58c
  • podman-tests-4.4.1-13.el9_2.tuxcare.els16.x86_64.rpm
    sha:79d8c280222c57b4d5dfb9e7e8c23e6e019d46e9ff835754bdb3160528fa1884
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.