Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:23295 - Security Advisory
Issued:
2025-12-16
Updated:
2025-12-18

RHSA-2025:23295 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: podman security update

Type/Severity

Security Advisory: Moderate

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for podman is now available for Red Hat Enterprise Linux 10.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The podman tool manages pods, container images, and containers. It is part of the libpod library, which is for applications that use container pods. Container pods is a concept in Kubernetes.

Security Fix(es):

  • golang: archive/tar: Unbounded allocation when parsing GNU sparse map (CVE-2025-58183)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 10 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 10 s390x
  • Red Hat Enterprise Linux for Power, little endian 10 ppc64le
  • Red Hat Enterprise Linux for ARM 64 10 aarch64
  • Red Hat CodeReady Linux Builder for x86_64 10 x86_64
  • Red Hat CodeReady Linux Builder for Power, little endian 10 ppc64le
  • Red Hat CodeReady Linux Builder for ARM 64 10 aarch64
  • Red Hat CodeReady Linux Builder for IBM z Systems 10 s390x

Fixes

  • BZ - 2407258 - CVE-2025-58183 golang: archive/tar: Unbounded allocation when parsing GNU sparse map
  • RHEL-132532 - runc 1.2.x upgrade throws error while using nocopy volume mount filesystem option - [RHEL 10.1]

CVEs

  • CVE-2025-58183

References

  • https://access.redhat.com/security/updates/classification/#moderate
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 10

SRPM
podman-5.6.0-8.el10_1.src.rpm SHA-256: 459cedde4d687a8cb9ae0d3ba94f161b87f3c5371df4f80dc76a2bfe4df85f02
x86_64
podman-5.6.0-8.el10_1.x86_64.rpm SHA-256: 011abaacf6d46149aec8c2e171542944137803ca2ba9efc4161a03a4001da73b
podman-debuginfo-5.6.0-8.el10_1.x86_64.rpm SHA-256: 2fef64100ead4db6104a8a639fe7a503629938710a05fd387ab1ba9642cf910c
podman-debugsource-5.6.0-8.el10_1.x86_64.rpm SHA-256: fa1371e02e84e774af19fce2d230a1d643332394e2b2e8ce2bd1b6823777dfb5
podman-docker-5.6.0-8.el10_1.noarch.rpm SHA-256: fc7a5d67fbd14eb757af6e8a3774d92452403b6685a469c207bbfdf6a6d69898
podman-remote-5.6.0-8.el10_1.x86_64.rpm SHA-256: e25efc831c27428a7d170fd03456f6ebe7bffcc6cc4a38c9e6f6ce143aca14f2
podman-remote-debuginfo-5.6.0-8.el10_1.x86_64.rpm SHA-256: 8f903f07af245ec063515a752a67cf7e32ac9408ff035287276f1b1aab032c75
podman-tests-debuginfo-5.6.0-8.el10_1.x86_64.rpm SHA-256: 24b861573ba2ce75537da98603ab5c8ed6ea75c0b3476b7404ec802715012f8c

Red Hat Enterprise Linux for IBM z Systems 10

SRPM
podman-5.6.0-8.el10_1.src.rpm SHA-256: 459cedde4d687a8cb9ae0d3ba94f161b87f3c5371df4f80dc76a2bfe4df85f02
s390x
podman-5.6.0-8.el10_1.s390x.rpm SHA-256: 0cb0a2513bb8a76ffff6be4e68e1a4ab845d5e2fe7cf8bc09b94f5f9e1a5b834
podman-debuginfo-5.6.0-8.el10_1.s390x.rpm SHA-256: 27faaba99af5f6764065849aa46f2dcbc7252819df0dfbeac44d8b84aa0a24bf
podman-debugsource-5.6.0-8.el10_1.s390x.rpm SHA-256: a9e63808bbfc82feb55129d5296172b8eb2bcfd09738681b2b93e5a8b61b719e
podman-docker-5.6.0-8.el10_1.noarch.rpm SHA-256: fc7a5d67fbd14eb757af6e8a3774d92452403b6685a469c207bbfdf6a6d69898
podman-remote-5.6.0-8.el10_1.s390x.rpm SHA-256: e24703a3cda980098e75ea0719a23e2e348e4260dbfacc02d09a441c0697fd21
podman-remote-debuginfo-5.6.0-8.el10_1.s390x.rpm SHA-256: 5f4e9774bcfe284b59ea8e2f059b6338834b6dd9ad624e950816a99ff9e4b6b8
podman-tests-debuginfo-5.6.0-8.el10_1.s390x.rpm SHA-256: 133dbb0d2d8025d0ebc3d2031b31c5e24f4df3a9a38f51ac2c1d131b8f1e5f44

Red Hat Enterprise Linux for Power, little endian 10

SRPM
podman-5.6.0-8.el10_1.src.rpm SHA-256: 459cedde4d687a8cb9ae0d3ba94f161b87f3c5371df4f80dc76a2bfe4df85f02
ppc64le
podman-5.6.0-8.el10_1.ppc64le.rpm SHA-256: cd82773293947dd048502d49ce747cf3ebc4fb7744fe4de469295d8453f43963
podman-debuginfo-5.6.0-8.el10_1.ppc64le.rpm SHA-256: f11aeb81e01c7942a1478b30a82e917279595f84438a7d64b682fe5257a0c974
podman-debugsource-5.6.0-8.el10_1.ppc64le.rpm SHA-256: 3550e55eba6d260a1b5d9971a48748ca60aefab243aa37d50719081e86211f14
podman-docker-5.6.0-8.el10_1.noarch.rpm SHA-256: fc7a5d67fbd14eb757af6e8a3774d92452403b6685a469c207bbfdf6a6d69898
podman-remote-5.6.0-8.el10_1.ppc64le.rpm SHA-256: 65f6d1b5d2dc26e87895b8bfd5580a08eff473c2fa7a2680b6da6adc0bfdb076
podman-remote-debuginfo-5.6.0-8.el10_1.ppc64le.rpm SHA-256: 166c395bf55994d7822634e8c10fd644bbb478cdde731f39c4b441d9c15f174c
podman-tests-debuginfo-5.6.0-8.el10_1.ppc64le.rpm SHA-256: cfc91a4bd57913822ed79e5500fff41b0ddfe9a317a4c22db129290fa81e738e

Red Hat Enterprise Linux for ARM 64 10

SRPM
podman-5.6.0-8.el10_1.src.rpm SHA-256: 459cedde4d687a8cb9ae0d3ba94f161b87f3c5371df4f80dc76a2bfe4df85f02
aarch64
podman-5.6.0-8.el10_1.aarch64.rpm SHA-256: 51500bfe70fb1af711f0307f6772bcb0b44df693fbada72f95d16a18a64913d9
podman-debuginfo-5.6.0-8.el10_1.aarch64.rpm SHA-256: c20f32a988a798ba6b02e7c8e7f73888ef556f188e7fa87f9e2931db2e109508
podman-debugsource-5.6.0-8.el10_1.aarch64.rpm SHA-256: 53d7f419d0907c890427e4a92ef1bd7be04f4ae9aaf34884759232b0f3ffb188
podman-docker-5.6.0-8.el10_1.noarch.rpm SHA-256: fc7a5d67fbd14eb757af6e8a3774d92452403b6685a469c207bbfdf6a6d69898
podman-remote-5.6.0-8.el10_1.aarch64.rpm SHA-256: 9185823d00235750d52d24d6b2a24e32c566360e88a2077b4e26d96462b8eaba
podman-remote-debuginfo-5.6.0-8.el10_1.aarch64.rpm SHA-256: 93da1a23338352ecd9d64d1e35ffd4b74bcbe0c1bc5af7dacb6cf67c1267e60f
podman-tests-debuginfo-5.6.0-8.el10_1.aarch64.rpm SHA-256: 09c85dbe760c61faa440ac8a5736ec5afd58bafec99a2e3b5396fac44eb73e08

Red Hat CodeReady Linux Builder for x86_64 10

SRPM
x86_64
podman-debuginfo-5.6.0-8.el10_1.x86_64.rpm SHA-256: 2fef64100ead4db6104a8a639fe7a503629938710a05fd387ab1ba9642cf910c
podman-debugsource-5.6.0-8.el10_1.x86_64.rpm SHA-256: fa1371e02e84e774af19fce2d230a1d643332394e2b2e8ce2bd1b6823777dfb5
podman-remote-debuginfo-5.6.0-8.el10_1.x86_64.rpm SHA-256: 8f903f07af245ec063515a752a67cf7e32ac9408ff035287276f1b1aab032c75
podman-tests-5.6.0-8.el10_1.x86_64.rpm SHA-256: 48abde58cf1c666263c8a6aeacfd9cb5796fdaad7dec6bcc4cbd04eb1ce5ce1a
podman-tests-debuginfo-5.6.0-8.el10_1.x86_64.rpm SHA-256: 24b861573ba2ce75537da98603ab5c8ed6ea75c0b3476b7404ec802715012f8c

Red Hat CodeReady Linux Builder for Power, little endian 10

SRPM
ppc64le
podman-debuginfo-5.6.0-8.el10_1.ppc64le.rpm SHA-256: f11aeb81e01c7942a1478b30a82e917279595f84438a7d64b682fe5257a0c974
podman-debugsource-5.6.0-8.el10_1.ppc64le.rpm SHA-256: 3550e55eba6d260a1b5d9971a48748ca60aefab243aa37d50719081e86211f14
podman-remote-debuginfo-5.6.0-8.el10_1.ppc64le.rpm SHA-256: 166c395bf55994d7822634e8c10fd644bbb478cdde731f39c4b441d9c15f174c
podman-tests-5.6.0-8.el10_1.ppc64le.rpm SHA-256: 2b1d12f747739dd6001c1de31b8feabc457c4b06664d0c213fc30db5cf440cec
podman-tests-debuginfo-5.6.0-8.el10_1.ppc64le.rpm SHA-256: cfc91a4bd57913822ed79e5500fff41b0ddfe9a317a4c22db129290fa81e738e

Red Hat CodeReady Linux Builder for ARM 64 10

SRPM
aarch64
podman-debuginfo-5.6.0-8.el10_1.aarch64.rpm SHA-256: c20f32a988a798ba6b02e7c8e7f73888ef556f188e7fa87f9e2931db2e109508
podman-debugsource-5.6.0-8.el10_1.aarch64.rpm SHA-256: 53d7f419d0907c890427e4a92ef1bd7be04f4ae9aaf34884759232b0f3ffb188
podman-remote-debuginfo-5.6.0-8.el10_1.aarch64.rpm SHA-256: 93da1a23338352ecd9d64d1e35ffd4b74bcbe0c1bc5af7dacb6cf67c1267e60f
podman-tests-5.6.0-8.el10_1.aarch64.rpm SHA-256: 4e822d3a21ddc9d8a7e257f04fdcba0f4f41b1dfd06daf28aeb4e718af9ad837
podman-tests-debuginfo-5.6.0-8.el10_1.aarch64.rpm SHA-256: 09c85dbe760c61faa440ac8a5736ec5afd58bafec99a2e3b5396fac44eb73e08

Red Hat CodeReady Linux Builder for IBM z Systems 10

SRPM
s390x
podman-debuginfo-5.6.0-8.el10_1.s390x.rpm SHA-256: 27faaba99af5f6764065849aa46f2dcbc7252819df0dfbeac44d8b84aa0a24bf
podman-debugsource-5.6.0-8.el10_1.s390x.rpm SHA-256: a9e63808bbfc82feb55129d5296172b8eb2bcfd09738681b2b93e5a8b61b719e
podman-remote-debuginfo-5.6.0-8.el10_1.s390x.rpm SHA-256: 5f4e9774bcfe284b59ea8e2f059b6338834b6dd9ad624e950816a99ff9e4b6b8
podman-tests-5.6.0-8.el10_1.s390x.rpm SHA-256: 4d9202a9e5164c5a0fa3e398d03501d82fbaca538f21c7095a062515572e84dd
podman-tests-debuginfo-5.6.0-8.el10_1.s390x.rpm SHA-256: 133dbb0d2d8025d0ebc3d2031b31c5e24f4df3a9a38f51ac2c1d131b8f1e5f44

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility