ELSA-2025-7391

ELSA-2025-7391 - podman security update

Type:SECURITY
Impact:IMPORTANT
Release Date:2025-05-21

Description


[5.4.0-9.0.1]
- Add devices on container startup, not on creation
- overlay: Put should ignore ENINVAL for Unmount [Orabug: 36234694]
- Drop nmap-ncat requirement and skip ignore-socket test case [Orabug: 34117404]

[5:5.4.0-9]
- update to the latest content of https://github.com/containers/podman/tree/v5.4-rhel
(https://github.com/containers/podman/commit/0ee1d49)
- fixes 'Rootless container libpod/tmp/persist directories not cleaned up, fill up tmpfs - [RHEL 9.6] 0day'
- Resolves: RHEL-86544

[5:5.4.0-8]
- update to the latest content of https://github.com/containers/podman/tree/v5.4-rhel
(https://github.com/containers/podman/commit/a994a04)
- fixes 'podman tests are failing - [RHEL 9.6] 0day'
- Resolves: RHEL-86092

[5:5.4.0-7]
- update to the latest content of https://github.com/containers/podman/tree/v5.4-rhel
(https://github.com/containers/podman/commit/f7bf65c)
- fixes 'Importing a tar.xz archive as a container fails with error 'layer 0 <...> does not match config's DiffID' - [RHEL 9.6] 0day'
- Resolves: RHEL-85218

[5:5.4.0-6]
- update to the latest content of https://github.com/containers/podman/tree/v5.4-rhel
(https://github.com/containers/podman/commit/9ad4842)
- fixes 'CVE-2025-22869 podman: Potential denial of service in golang.org/x/crypto [rhel-9.6]'
- Resolves: RHEL-81319

[5:5.4.0-5]
- update to the latest content of https://github.com/containers/podman/tree/v5.4-rhel
(https://github.com/containers/podman/commit/9d2e54f)
- fixes 'Excessive memory leak due to uncontrolled accumulation of health.log entries in Podman 5.x - [RHEL - 9.6] ZeroDay'
- Resolves: RHEL-83557

[5:5.4.0-4]
- update to the latest content of https://github.com/containers/podman/tree/v5.4-rhel
(https://github.com/containers/podman/commit/45c2d1f)
- Resolves: RHEL-82970

[5:5.4.0-3]
- update to the latest content of https://github.com/containers/podman/tree/v5.4-rhel
(https://github.com/containers/podman/commit/e48006b)
- Resolves: RHEL-82198

[5:5.4.0-2]
- update to the latest content of https://github.com/containers/podman/tree/v5.4-rhel
(https://github.com/containers/podman/commit/2adbe89)
- Resolves: RHEL-79694


Related CVEs


CVE-2025-22869
CVE-2025-27144

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 9 (aarch64) podman-5.4.0-9.0.1.el9_6.src.rpmeb67cb521d2f1a15bdfada206a76243cd98d0452db19388b274bea7ea0c88817-ol9_aarch64_appstream
podman-5.4.0-9.0.1.el9_6.aarch64.rpmaab26963931cd3d74861a7c4614d3d158e1430bc624b77a39738f2fe4dfedf3f-ol9_aarch64_appstream
podman-docker-5.4.0-9.0.1.el9_6.noarch.rpm10fcecbbb3843a26b7547bd3bcb5236b02a7ba1e9d801cc8264908d7ff3a13a7-ol9_aarch64_appstream
podman-plugins-5.4.0-9.0.1.el9_6.aarch64.rpm42ace0e18842298182659e435e16540fe1effeafb73b23ae6c81bdc0b2704114-ol9_aarch64_appstream
podman-remote-5.4.0-9.0.1.el9_6.aarch64.rpm3477d13442c72bd342a406badaae9f89c74ca1796142f622fd970e74f9d258aa-ol9_aarch64_appstream
podman-tests-5.4.0-9.0.1.el9_6.aarch64.rpm2d9860216ae0ff99d11db8a4f9f0aa6dbc342495a223f8f2723b50c22c29617f-ol9_aarch64_appstream
Oracle Linux 9 (x86_64) podman-5.4.0-9.0.1.el9_6.src.rpmeb67cb521d2f1a15bdfada206a76243cd98d0452db19388b274bea7ea0c88817-ol9_x86_64_appstream
podman-5.4.0-9.0.1.el9_6.x86_64.rpm41400e212f34a370e76449f53e273e31e475798aeab516f3272002bf434b5203-ol9_x86_64_appstream
podman-docker-5.4.0-9.0.1.el9_6.noarch.rpm10fcecbbb3843a26b7547bd3bcb5236b02a7ba1e9d801cc8264908d7ff3a13a7-ol9_x86_64_appstream
podman-plugins-5.4.0-9.0.1.el9_6.x86_64.rpmf8af99d1e2ad1dfd1d8995e4d21bcaf9438e85386da7bbe08b678a9099f82414-ol9_x86_64_appstream
podman-remote-5.4.0-9.0.1.el9_6.x86_64.rpmeedb53641a46632ecc982d7e55de510f56ac64177ed6fabb8daf13caede1ea31-ol9_x86_64_appstream
podman-tests-5.4.0-9.0.1.el9_6.x86_64.rpma087ed64d21f2689cc19dc69d0abd43db641b81f2aac999bcd1e4deec0d0e8e3-ol9_x86_64_appstream



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete