GPU VulnDB

Database/Container, Kubernetes & orchestration

Podman: quadlet install --replace does not truncate, leaving stale options in the new unit

CVSS 4.2CVE-2026-19730Container, Kubernetes & orchestrationcurated

Impact

On hosts where Quadlet units drive container workloads, replacing a unit file with a shorter one silently leaves trailing bytes of the old file in place, because the destination is opened without O_TRUNC and the io.Copy fallback is taken whenever reflink is unavailable (which includes common RHEL XFS setups). An operator who edits a Quadlet to drop a trailing security option - removing an AddCapability line, tightening a Volume mount - gets a success with no warning while the old line is still honoured. The practical risk on a GPU node is a container that keeps a capability or a host bind mount the operator believes was removed, so later image updates expose host paths into a workload container. There is no information disclosure to a new party: the actor already had write access to the Quadlet.

Who can reach it

Local, authenticated user who already manages Quadlet units on the host, combined with an unlucky filesystem and an edit that shortens the file. Not remotely reachable and not a privilege boundary crossing on its own; the exposure comes from the operator's intended hardening failing to apply.

What to do

Update the podman package from the Red Hat errata (RHSA-2026:69961, RHSA-2026:70201) or an equivalent upstream build and re-run the affected quadlet install --replace operations. No daemon or node restart is needed, but any unit installed with --replace since the last change should be diffed against its source, since a bad file persists after patching; restarting the affected containers is required for a corrected unit to take effect.

References

Related entries

All Container, Kubernetes & orchestration entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.