UBUNTU-CVE-2026-19730

Source
https://ubuntu.com/security/CVE-2026-19730
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-19730.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2026-19730
Upstream
  • CVE-2026-19730
Published
2026-08-17T00:00:00Z
Modified
2026-08-17T12:30:30.816362274Z
Severity
  • 4.2 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

The 'podman quadlet install --replace' command opens the existing destination file with OCREATE|OWRONLY but omits OTRUNC. When the initial reflink copy attempt fails (common on non-reflink-capable filesystems including many RHEL default XFS configurations), the fallback in ReflinkOrCopy uses io.Copy which performs a non-truncating write. If the original Quadlet is larger than the new Quadlet, the file is not truncated and content from the original is preserved. The command completes with no warning. There is no risk of information leakage as the user already had access to the Quadlet in order to replace it, and in most cases, this would only lead to invalid Quadlet files. However, security-related options from the end of the old Quadlet could be included in the new Quadlet, and if the truncation resulted in a valid Quadlet file, this could result in undesirable behavior. For example, running podman quadlet install --replace to remove a single line from the end of a Quadlet - including security-sensitive content, like AddCapability - will fail, and the option will continue to be used. Further, with Volume Quadlets, this can include additional mounts which can cause content to be unintentionally exposed into containers. If, later, the image is updated then compromised content might be leaked to an attacker. The vulnerable code paths are in pkg/domain/infra/abi/quadlet.go (lines 338-360, OCREATE|OWRONLY without OTRUNC) and vendor/go.podman.io/storage/pkg/fileutils/reflink_linux.go (lines 12-19, non-truncating io.Copy fallback).

References

Affected packages

Ubuntu:26.04:LTS / podman

Package

Name
podman
Purl
pkg:deb/ubuntu/podman?arch=source&distro=resolute

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

5.*
5.4.2+ds1-2
5.7.0+ds2-3
5.7.0+ds2-3build1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "podman",
            "binary_version": "5.7.0+ds2-3build1"
        },
        {
            "binary_name": "podman-docker",
            "binary_version": "5.7.0+ds2-3build1"
        },
        {
            "binary_name": "podman-remote",
            "binary_version": "5.7.0+ds2-3build1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-19730.json"