Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:23325 - Security Advisory
Issued:
2025-12-16
Updated:
2025-12-18

RHSA-2025:23325 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: podman security update

Type/Severity

Security Advisory: Moderate

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for podman is now available for Red Hat Enterprise Linux 9.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The podman tool manages pods, container images, and containers. It is part of the libpod library, which is for applications that use container pods. Container pods is a concept in Kubernetes.

Security Fix(es):

  • golang: archive/tar: Unbounded allocation when parsing GNU sparse map (CVE-2025-58183)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 9 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 9 s390x
  • Red Hat Enterprise Linux for Power, little endian 9 ppc64le
  • Red Hat Enterprise Linux for ARM 64 9 aarch64

Fixes

  • BZ - 2407258 - CVE-2025-58183 golang: archive/tar: Unbounded allocation when parsing GNU sparse map
  • RHEL-132531 - runc 1.2.x upgrade throws error while using nocopy volume mount filesystem option - [RHEL 9.7]

CVEs

  • CVE-2025-58183

References

  • https://access.redhat.com/security/updates/classification/#moderate
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 9

SRPM
podman-5.6.0-9.el9_7.src.rpm SHA-256: 3394760ff7c7e882200fffc2e3422477f5a8ebc36c4dab2a8ef9c6b1f2887471
x86_64
podman-5.6.0-9.el9_7.x86_64.rpm SHA-256: d5ceaec0f70ede851be7a829b85282c3f7a6ebf5a45dfdc76d2623d0ff392d95
podman-debuginfo-5.6.0-9.el9_7.x86_64.rpm SHA-256: ae69f305e843adc28b3737eb9c69dbde638db20a197933152019b87897fbda04
podman-debugsource-5.6.0-9.el9_7.x86_64.rpm SHA-256: 7c8786ee7a7df50ef0e5b35c8cf276df07fc018be4c44f022842bc188e7563be
podman-docker-5.6.0-9.el9_7.noarch.rpm SHA-256: 544c5e37a5dc711bdb12c2eb60e98d13e75255a43215f10e945c26e491d2bc62
podman-plugins-5.6.0-9.el9_7.x86_64.rpm SHA-256: e99f34bbab98dc95a39b5267086cb6b6d837594bc36d9b20a9db575c075b8086
podman-plugins-debuginfo-5.6.0-9.el9_7.x86_64.rpm SHA-256: cd71985ec833d1dcbfe6a9c0cbd523dc32ca81417e62d99b828bd375c703e437
podman-remote-5.6.0-9.el9_7.x86_64.rpm SHA-256: 5f8bea8a492de25a6393643cad7f9f593473e5e83d6fb661b6a9b2190387a22d
podman-remote-debuginfo-5.6.0-9.el9_7.x86_64.rpm SHA-256: 7fab840832a342d87364f4abb931f3eebe68a3d54cce9d0fbeb41ac7948c7255
podman-tests-5.6.0-9.el9_7.x86_64.rpm SHA-256: b6d60e8552f97e274db8d542df768cf92acdc86f426b9c0aacbab22301a72a2c
podman-tests-debuginfo-5.6.0-9.el9_7.x86_64.rpm SHA-256: 911155fd135f001ad15fdf17a26ca90b2dbf9c9bfd3ac72ad33a4280551b985c

Red Hat Enterprise Linux for IBM z Systems 9

SRPM
podman-5.6.0-9.el9_7.src.rpm SHA-256: 3394760ff7c7e882200fffc2e3422477f5a8ebc36c4dab2a8ef9c6b1f2887471
s390x
podman-5.6.0-9.el9_7.s390x.rpm SHA-256: 219290b6f04c81d71324b16be1b2e907814569c66581099ac7138adcf22c91d4
podman-debuginfo-5.6.0-9.el9_7.s390x.rpm SHA-256: 55780717eaa05caf99997d85e8289eae862c4df3e0c2faf1754ee445496f2b6b
podman-debugsource-5.6.0-9.el9_7.s390x.rpm SHA-256: d256b685ee95d0a95dd29af50db45a7b9b88c4bebf30073a47b819654ac692f6
podman-docker-5.6.0-9.el9_7.noarch.rpm SHA-256: 544c5e37a5dc711bdb12c2eb60e98d13e75255a43215f10e945c26e491d2bc62
podman-plugins-5.6.0-9.el9_7.s390x.rpm SHA-256: 0f6bf89c09e0b320608e0b1b4162f493d48a15d1732ed9a98a0a6520dfc3c90f
podman-plugins-debuginfo-5.6.0-9.el9_7.s390x.rpm SHA-256: e0bca54ceb6cbf1b48824099b721f8d53b26117714951bb240fc39e734e58c99
podman-remote-5.6.0-9.el9_7.s390x.rpm SHA-256: 3b85697201a0fc5770f0b05a0dbc56e05d0d288cfd4f8393f71cafcf378b7f3a
podman-remote-debuginfo-5.6.0-9.el9_7.s390x.rpm SHA-256: 47a7223cfb6d70d0d47c67c91434e3710ebaec10c34e6acd51c8052cca333765
podman-tests-5.6.0-9.el9_7.s390x.rpm SHA-256: 73617e55988b973387c11833c7402ad0d64595b18b3adc5565991116b22962ef
podman-tests-debuginfo-5.6.0-9.el9_7.s390x.rpm SHA-256: a0d6d3f42ef04d3492ec1c9afca2f7e56ff7b180c9fec835c5152e9c1202fbda

Red Hat Enterprise Linux for Power, little endian 9

SRPM
podman-5.6.0-9.el9_7.src.rpm SHA-256: 3394760ff7c7e882200fffc2e3422477f5a8ebc36c4dab2a8ef9c6b1f2887471
ppc64le
podman-5.6.0-9.el9_7.ppc64le.rpm SHA-256: 32706ebedcf937d107705affaca6f92ff0569c951cb6c3fe095ccbb82d33b11c
podman-debuginfo-5.6.0-9.el9_7.ppc64le.rpm SHA-256: 9da351eefea1359893bfdb6609c2182693756a21ef9cacf3c08eb37e4a828c7e
podman-debugsource-5.6.0-9.el9_7.ppc64le.rpm SHA-256: 5c4dcb89dfab99c1dd0d021515c654ce96b72e70612881b015818a684576ba11
podman-docker-5.6.0-9.el9_7.noarch.rpm SHA-256: 544c5e37a5dc711bdb12c2eb60e98d13e75255a43215f10e945c26e491d2bc62
podman-plugins-5.6.0-9.el9_7.ppc64le.rpm SHA-256: 88fb8f5c226df95a8fb3c4ea64522ad84572ab6015b1dc278f43af2c1e89f79d
podman-plugins-debuginfo-5.6.0-9.el9_7.ppc64le.rpm SHA-256: e38b51bc87b5b8038982c1e76ab945cbf13493cbe9e9f066c11a01f28a152954
podman-remote-5.6.0-9.el9_7.ppc64le.rpm SHA-256: 1d82ed90a3944f8990d274460896584ad45f20ea82abc777bc4ad8d05e00fbd9
podman-remote-debuginfo-5.6.0-9.el9_7.ppc64le.rpm SHA-256: dcc3de0886806bc3b08ee9006d78a0ab58376d76c99cd0f655acad9152dc76b2
podman-tests-5.6.0-9.el9_7.ppc64le.rpm SHA-256: 5f2543fee4f180f03746ea9bf874ff9139ac047efff0a73063f2ddb8178537d3
podman-tests-debuginfo-5.6.0-9.el9_7.ppc64le.rpm SHA-256: 9fda23cd31b6f3f3f6b71637f30f385c8e0d63ff42acc47229964deac12d2abc

Red Hat Enterprise Linux for ARM 64 9

SRPM
podman-5.6.0-9.el9_7.src.rpm SHA-256: 3394760ff7c7e882200fffc2e3422477f5a8ebc36c4dab2a8ef9c6b1f2887471
aarch64
podman-5.6.0-9.el9_7.aarch64.rpm SHA-256: b7c8d657736ba93ce2ecbf99ccaa08953dc3c7dd395ac971c9c14d50535336da
podman-debuginfo-5.6.0-9.el9_7.aarch64.rpm SHA-256: de3fbf000d99ed1acb6d07a2231b12efe63ed9e9569618222b21e90950739c79
podman-debugsource-5.6.0-9.el9_7.aarch64.rpm SHA-256: 38780c3eb20fb7fc89ffc52e39f377c43431990a820aeffc656cf52d97de59d6
podman-docker-5.6.0-9.el9_7.noarch.rpm SHA-256: 544c5e37a5dc711bdb12c2eb60e98d13e75255a43215f10e945c26e491d2bc62
podman-plugins-5.6.0-9.el9_7.aarch64.rpm SHA-256: 628a5756f88ca6c2341e2871988d86e2a2e9c1428ae4244bae33b7ce31afebf2
podman-plugins-debuginfo-5.6.0-9.el9_7.aarch64.rpm SHA-256: 60b1180a0f330d48703ee99dc3237bfea342f78ae3abc34a5d45f4d6fa33dcd7
podman-remote-5.6.0-9.el9_7.aarch64.rpm SHA-256: ea829b52ba528a79b52a066496a1b90ecb8412d9fc31ce857d8c4bf3d5cd79f1
podman-remote-debuginfo-5.6.0-9.el9_7.aarch64.rpm SHA-256: f0e577f07f95118dd5d42f92a6b128ffbc463638a6337cbdb7759c0a146322a0
podman-tests-5.6.0-9.el9_7.aarch64.rpm SHA-256: fa89cf413722a28d6eb99021a15ea0f0074822bb584f41f03b86576f6a7e62a6
podman-tests-debuginfo-5.6.0-9.el9_7.aarch64.rpm SHA-256: 9065d03eb6d1fc74d83b3b1a1841b83bcbb27d9ca3c90aaa7ebce1f6c0344221

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility