MEDIUM 4.2 GitHub

CVE-2026-19730

podman quadlet install --replace does not fully replace the old file

### Impact When running `podman quadlet install --replace` to replace a Quadlet file, if the original Quadlet is larger than the new Quadlet, the file would not be truncated and content from the original would be preserved. There is no risk of information leakage as the user already had access to the Quadlet in order to replace it, and in most cases, this would only lead to invalid Quadlet files (see https://github.com/podman-container-tools/podman/issues/29013). However, security-related optio

Affected Products

References

Published: 2026-09-24 · Source: GitHub · Feed updated: 2026-09-27
This medium severity vulnerability with a CVSS score of 4.2 was published on 2026-09-24 via GitHub. Affected: go/github.com/containers/podman/v5 >= 5.7.0, < 5.8.6.
vulnfeed aggregates 11720 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.