git: f71fa0198a36 - main - security/vuxml: document podman vulnerability

Sergey A. Osokin <[email protected]>
Newsgroups gmane.os.freebsd.devel.cvs.ports
Message-ID <[email protected]>
The branch main has been updated by osa:

URL: https://cgit.FreeBSD.org/ports/commit/?id=f71fa0198a369d9113328203e0210289f6b0c7dd

commit f71fa0198a369d9113328203e0210289f6b0c7dd
Author:     Sergey A. Osokin <[email protected]>
AuthorDate: 2026-08-19 03:14:24 +0000
Commit:     Sergey A. Osokin <[email protected]>
CommitDate: 2026-08-19 03:14:24 +0000

    security/vuxml: document podman vulnerability
    
    Sponsored by:   tipi.work
---
 security/vuxml/vuln/2026.xml | 30 ++++++++++++++++++++++++++++++
 1 file changed, 30 insertions(+)

diff --git a/security/vuxml/vuln/2026.xml b/security/vuxml/vuln/2026.xml
index 2de485ad0f11..27f332da44ff 100644
--- a/security/vuxml/vuln/2026.xml
+++ b/security/vuxml/vuln/2026.xml
@@ -1,3 +1,33 @@
+  <vuln vid="01c15468-9b7b-11f1-a75c-589cfc10a551">
+    <topic>podman -- podman quadlet install --replace does not fully replace the old file</topic>
+    <affects>
+	<package>
+	<name>podman</name>
+	<range><ge>5.7.0</ge><lt>5.8.6</lt></range>
+	</package>
+    </affects>
+    <description>
+	<body xmlns="http://www.w3.org/1999/xhtml">
+	<p>The Podman developers report:</p>
+	<blockquote cite="https://github.com/podman-container-tools/podman/security/advisories/GHSA-fx76-2j3w-2mx6">
+	  <p>When running podman quadlet install --replace to replace a
+	   Quadlet file, if the original Quadlet is larger than the new
+	   Quadlet, the file would not be truncated and content from the
+	   original would be preserved.</p>
+	</blockquote>
+	</body>
+    </description>
+    <references>
+      <cvename>CVE-2026-19730</cvename>
+      <url>https://github.com/podman-container-tools/podman/releases/tag/v5.8.6</url>
+      <url>https://github.com/podman-container-tools/podman/security/advisories/GHSA-fx76-2j3w-2mx6</url>
+    </references>
+    <dates>
+      <discovery>2026-08-13</discovery>
+      <entry>2026-08-18</entry>
+    </dates>
+  </vuln>
+
   <vuln vid="3a65fb7e-9ac2-11f1-bdc8-2cf05da270f3">
     <topic>Gitlab -- Vulnerabilities</topic>
     <affects>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.