Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
红帽产品勘误 RHSA-2026:3336 - Security Advisory
发布:
2026-02-25
已更新:
2026-02-25

RHSA-2026:3336 - Security Advisory

  • 概述
  • 更新的软件包

概述

Important: podman security update

类型/严重性

Security Advisory: Important

Red Hat Lightspeed patch analysis

识别并修复受此公告影响的系统。

查看受影响的系统

标题

An update for podman is now available for Red Hat Enterprise Linux 10.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

描述

The podman tool manages pods, container images, and containers. It is part of the libpod library, which is for applications that use container pods. Container pods is a concept in Kubernetes.

Security Fix(es):

  • crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate (CVE-2025-61729)
  • golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip (CVE-2025-61728)
  • golang: net/url: Memory exhaustion in query parameter parsing in net/url (CVE-2025-61726)
  • crypto/tls: Unexpected session resumption in crypto/tls (CVE-2025-68121)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

解决方案

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

受影响的产品

  • Red Hat Enterprise Linux for x86_64 10 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 10 s390x
  • Red Hat Enterprise Linux for Power, little endian 10 ppc64le
  • Red Hat Enterprise Linux for ARM 64 10 aarch64
  • Red Hat CodeReady Linux Builder for x86_64 10 x86_64
  • Red Hat CodeReady Linux Builder for Power, little endian 10 ppc64le
  • Red Hat CodeReady Linux Builder for ARM 64 10 aarch64
  • Red Hat CodeReady Linux Builder for IBM z Systems 10 s390x

修复

  • BZ - 2418462 - CVE-2025-61729 crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate
  • BZ - 2434431 - CVE-2025-61728 golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip
  • BZ - 2434432 - CVE-2025-61726 golang: net/url: Memory exhaustion in query parameter parsing in net/url
  • BZ - 2437111 - CVE-2025-68121 crypto/tls: Unexpected session resumption in crypto/tls

CVE

  • CVE-2025-61726
  • CVE-2025-61728
  • CVE-2025-61729
  • CVE-2025-68121

参考

  • https://access.redhat.com/security/updates/classification/#important
注:: 可能有这些软件包的更新版本。 点击软件包名称查看详情。

Red Hat Enterprise Linux for x86_64 10

SRPM
podman-5.6.0-12.el10_1.src.rpm SHA-256: fff69b3590d2ac6d9d3621f314b5108a4857ce11019db9243f4606177adf9754
x86_64
podman-5.6.0-12.el10_1.x86_64.rpm SHA-256: 4951a329040ad488ca9fc0094a094918656e2847ed23c91d3ad26e5f714476f3
podman-debuginfo-5.6.0-12.el10_1.x86_64.rpm SHA-256: 4ca1bde491df986fabf15b9caa802d1c1db7e2f8b5a0dd8e3d20e75ce3a2ddac
podman-debugsource-5.6.0-12.el10_1.x86_64.rpm SHA-256: 9894869c2df185e76a5c119d081350b3f89358b1fb76bfadc46563d3a9f186ce
podman-docker-5.6.0-12.el10_1.noarch.rpm SHA-256: 542e74fc85a7c374e59babbd9162993dc99642809e0af844dc7e03e5cc9b8a44
podman-remote-5.6.0-12.el10_1.x86_64.rpm SHA-256: f27f5fe046c33573a19bdda1a6685f481804d1604465db1d4b3d31cec3063701
podman-remote-debuginfo-5.6.0-12.el10_1.x86_64.rpm SHA-256: 7b6ac1490d6212a9d4902f155da2214d38d4835fbc340b4e9a1eab0cfa9eae70
podman-tests-debuginfo-5.6.0-12.el10_1.x86_64.rpm SHA-256: 0ac22c55d3138c43fcb3ea5ad62a290ca365c489d1bb97e588c8fb602a70db6d

Red Hat Enterprise Linux for IBM z Systems 10

SRPM
podman-5.6.0-12.el10_1.src.rpm SHA-256: fff69b3590d2ac6d9d3621f314b5108a4857ce11019db9243f4606177adf9754
s390x
podman-5.6.0-12.el10_1.s390x.rpm SHA-256: 2df976d7bbb7d488c531f1aa0316cdc3f8f5955e2745a669f3680164966b7e47
podman-debuginfo-5.6.0-12.el10_1.s390x.rpm SHA-256: ec7ab97813a47c5521c8ed95f858480b1f6ee2a347a0ffd7b5d6db951f93da0f
podman-debugsource-5.6.0-12.el10_1.s390x.rpm SHA-256: 1999dbde2c72db704065949038a581afea242cc3dd64891a1273f5c51a7acea5
podman-docker-5.6.0-12.el10_1.noarch.rpm SHA-256: 542e74fc85a7c374e59babbd9162993dc99642809e0af844dc7e03e5cc9b8a44
podman-remote-5.6.0-12.el10_1.s390x.rpm SHA-256: fe061d02b917139fb5327b151bccf05d172714a9dc4bfe71e02e7e3244fcc6df
podman-remote-debuginfo-5.6.0-12.el10_1.s390x.rpm SHA-256: 4994deda9227a764e761fa6ddaa19051d6393c29a787b47f116b936ed01c52dd
podman-tests-debuginfo-5.6.0-12.el10_1.s390x.rpm SHA-256: 7bb335bb8262fa35c2b36e7c406448dc0e1f2c8e91e897f2440373fb205beda6

Red Hat Enterprise Linux for Power, little endian 10

SRPM
podman-5.6.0-12.el10_1.src.rpm SHA-256: fff69b3590d2ac6d9d3621f314b5108a4857ce11019db9243f4606177adf9754
ppc64le
podman-5.6.0-12.el10_1.ppc64le.rpm SHA-256: 314c2c0d1bb3af2491315e20064891b491f395a562e5eaa33ce9d7952abd0b99
podman-debuginfo-5.6.0-12.el10_1.ppc64le.rpm SHA-256: 688dbae9f1ceebc00c93423cd2d94c2444c3a600051382312fb71ef94098f5ca
podman-debugsource-5.6.0-12.el10_1.ppc64le.rpm SHA-256: 92515a9830314745297da68f59451ac98b01d9d84c7d4480aef0841017bdfbc7
podman-docker-5.6.0-12.el10_1.noarch.rpm SHA-256: 542e74fc85a7c374e59babbd9162993dc99642809e0af844dc7e03e5cc9b8a44
podman-remote-5.6.0-12.el10_1.ppc64le.rpm SHA-256: 606355464fc0297c534984691fda7c111b75e8f066674d32b0bd589ae92e61a3
podman-remote-debuginfo-5.6.0-12.el10_1.ppc64le.rpm SHA-256: 87a15186bf939220c8efab82867ba0d1dd8adeade4475bc9ef166601c5995d71
podman-tests-debuginfo-5.6.0-12.el10_1.ppc64le.rpm SHA-256: 8459ddaa935e614dc1b350c4692b967627a65052647ba8b8d176bfef5e80b35f

Red Hat Enterprise Linux for ARM 64 10

SRPM
podman-5.6.0-12.el10_1.src.rpm SHA-256: fff69b3590d2ac6d9d3621f314b5108a4857ce11019db9243f4606177adf9754
aarch64
podman-5.6.0-12.el10_1.aarch64.rpm SHA-256: b7c2aaa30aa0658eb1c736913943825ede59f071017db1e62afd00cf28ab29ab
podman-debuginfo-5.6.0-12.el10_1.aarch64.rpm SHA-256: 8d742f607678510b43374ed3499ed6569827e7d8278c55c0e5b00d9fea618be1
podman-debugsource-5.6.0-12.el10_1.aarch64.rpm SHA-256: e5459feed35ccc83a358201b9c98a2404d46018d7b510b446eeb01c243073260
podman-docker-5.6.0-12.el10_1.noarch.rpm SHA-256: 542e74fc85a7c374e59babbd9162993dc99642809e0af844dc7e03e5cc9b8a44
podman-remote-5.6.0-12.el10_1.aarch64.rpm SHA-256: 63b3e39ac1de1703b4dd3dc3fa2042fb2c14fcb7492689e6f66813e2711962bc
podman-remote-debuginfo-5.6.0-12.el10_1.aarch64.rpm SHA-256: 90bd55fc72cc68048439e9e8ece97dc22be6955679aeca5741f071cea5c41475
podman-tests-debuginfo-5.6.0-12.el10_1.aarch64.rpm SHA-256: 87b754f00c11dd60958e410a14315e509616d8d39af6e2c629e22dea42b95a2f

Red Hat CodeReady Linux Builder for x86_64 10

SRPM
x86_64
podman-debuginfo-5.6.0-12.el10_1.x86_64.rpm SHA-256: 4ca1bde491df986fabf15b9caa802d1c1db7e2f8b5a0dd8e3d20e75ce3a2ddac
podman-debugsource-5.6.0-12.el10_1.x86_64.rpm SHA-256: 9894869c2df185e76a5c119d081350b3f89358b1fb76bfadc46563d3a9f186ce
podman-remote-debuginfo-5.6.0-12.el10_1.x86_64.rpm SHA-256: 7b6ac1490d6212a9d4902f155da2214d38d4835fbc340b4e9a1eab0cfa9eae70
podman-tests-5.6.0-12.el10_1.x86_64.rpm SHA-256: c2b08c341bfbe6d7e6c0db08e956a0d56e6cfe84cd84f003e7da45d5f881b603
podman-tests-debuginfo-5.6.0-12.el10_1.x86_64.rpm SHA-256: 0ac22c55d3138c43fcb3ea5ad62a290ca365c489d1bb97e588c8fb602a70db6d

Red Hat CodeReady Linux Builder for Power, little endian 10

SRPM
ppc64le
podman-debuginfo-5.6.0-12.el10_1.ppc64le.rpm SHA-256: 688dbae9f1ceebc00c93423cd2d94c2444c3a600051382312fb71ef94098f5ca
podman-debugsource-5.6.0-12.el10_1.ppc64le.rpm SHA-256: 92515a9830314745297da68f59451ac98b01d9d84c7d4480aef0841017bdfbc7
podman-remote-debuginfo-5.6.0-12.el10_1.ppc64le.rpm SHA-256: 87a15186bf939220c8efab82867ba0d1dd8adeade4475bc9ef166601c5995d71
podman-tests-5.6.0-12.el10_1.ppc64le.rpm SHA-256: 624654642f08dbdd35eff6c68c8d2388f35faae1b2f9cb9422fd4994b2bc7927
podman-tests-debuginfo-5.6.0-12.el10_1.ppc64le.rpm SHA-256: 8459ddaa935e614dc1b350c4692b967627a65052647ba8b8d176bfef5e80b35f

Red Hat CodeReady Linux Builder for ARM 64 10

SRPM
aarch64
podman-debuginfo-5.6.0-12.el10_1.aarch64.rpm SHA-256: 8d742f607678510b43374ed3499ed6569827e7d8278c55c0e5b00d9fea618be1
podman-debugsource-5.6.0-12.el10_1.aarch64.rpm SHA-256: e5459feed35ccc83a358201b9c98a2404d46018d7b510b446eeb01c243073260
podman-remote-debuginfo-5.6.0-12.el10_1.aarch64.rpm SHA-256: 90bd55fc72cc68048439e9e8ece97dc22be6955679aeca5741f071cea5c41475
podman-tests-5.6.0-12.el10_1.aarch64.rpm SHA-256: 6be5a07fb651782b689fcff49ce8a5d058ea083a2a91e79f434a591a349dc31a
podman-tests-debuginfo-5.6.0-12.el10_1.aarch64.rpm SHA-256: 87b754f00c11dd60958e410a14315e509616d8d39af6e2c629e22dea42b95a2f

Red Hat CodeReady Linux Builder for IBM z Systems 10

SRPM
s390x
podman-debuginfo-5.6.0-12.el10_1.s390x.rpm SHA-256: ec7ab97813a47c5521c8ed95f858480b1f6ee2a347a0ffd7b5d6db951f93da0f
podman-debugsource-5.6.0-12.el10_1.s390x.rpm SHA-256: 1999dbde2c72db704065949038a581afea242cc3dd64891a1273f5c51a7acea5
podman-remote-debuginfo-5.6.0-12.el10_1.s390x.rpm SHA-256: 4994deda9227a764e761fa6ddaa19051d6393c29a787b47f116b936ed01c52dd
podman-tests-5.6.0-12.el10_1.s390x.rpm SHA-256: 211f4818293350b90ff13cda0a29dc8574c6235107ecf5fe417fb02356c75fea
podman-tests-debuginfo-5.6.0-12.el10_1.s390x.rpm SHA-256: 7bb335bb8262fa35c2b36e7c406448dc0e1f2c8e91e897f2440373fb205beda6

Red Hat 安全团队联络方式为 secalert@redhat.com。 更多联络细节请参考 https://access.redhat.com/security/team/contact/。

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility