Skip to main content
EPSS 0.2%top 95%

CVE-2026-19730: Incomplete Cleanup in Red Hat Red Hat Enterprise Linux 10

0
Medium
VulnerabilityCVE-2026-19730cvecve-2026-19730
Published: 08/13/2026 (08/13/2026, 17:53:37 UTC)
Source: CVE Database V5
Vendor/Project: Red Hat
Product: Red Hat Enterprise Linux 10

Description

The 'podman quadlet install --replace' command opens the existing destination file with O_CREATE|O_WRONLY but omits O_TRUNC. When the initial reflink copy attempt fails (common on non-reflink-capable filesystems including many RHEL default XFS configurations), the fallback in ReflinkOrCopy uses io.Copy which performs a non-truncating write. If the original Quadlet is larger than the new Quadlet, the file is not truncated and content from the original is preserved. The command completes with no warning. There is no risk of information leakage as the user already had access to the Quadlet in order to replace it, and in most cases, this would only lead to invalid Quadlet files. However, security-related options from the end of the old Quadlet could be included in the new Quadlet, and if the truncation resulted in a valid Quadlet file, this could result in undesirable behavior. For example, running podman quadlet install --replace to remove a single line from the end of a Quadlet - including security-sensitive content, like AddCapability - will fail, and the option will continue to be used. Further, with Volume Quadlets, this can include additional mounts which can cause content to be unintentionally exposed into containers. If, later, the image is updated then compromised content might be leaked to an attacker. The vulnerable code paths are in pkg/domain/infra/abi/quadlet.go (lines 338-360, O_CREATE|O_WRONLY without O_TRUNC) and vendor/go.podman.io/storage/pkg/fileutils/reflink_linux.go (lines 12-19, non-truncating io.Copy fallback).

CVSS v3.1

Score 4.2medium

Attack Vector
Local
Attack Complexity
High
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
Low
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L

Affected software

Red Hat

Red Hat Enterprise Linux 10

Red Hat

Red Hat Enterprise Linux 9

Red Hat

Red Hat Ansible Automation Platform 2

Red Hat

Red Hat Enterprise Linux 8

Red Hat

Red Hat Hardened Images

Red Hat

Red Hat OpenShift Container Platform 4

Red Hat

Red Hat OpenShift Dev Spaces

Red Hat

Red Hat OpenShift Virtualization 4

Red Hat

Red Hat Quay 3

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/23/2026, 02:07:51 UTC

Technical Analysis

The 'podman quadlet install --replace' command opens the destination file with O_CREATE|O_WRONLY but omits O_TRUNC, so when the reflink copy fallback uses io.Copy, it performs a non-truncating write. If the original Quadlet file is larger than the new one, leftover content from the original remains, potentially including security-sensitive options like AddCapability or volume mounts. This can cause Podman to fail to enforce configuration changes intended by the administrator. The vulnerable code is in pkg/domain/infra/abi/quadlet.go (lines 338-360) and vendor/go.podman.io/storage/pkg/fileutils/reflink_linux.go (lines 12-19).

Potential Impact

The vulnerability does not allow information leakage or privilege escalation beyond the user's existing permissions. Instead, it causes Podman to fail to remove or update certain security-related configuration options in Quadlet files, potentially leading to unintended container behavior such as retention of capabilities or volume mounts. This could indirectly lead to exposure of host content into containers or compromised container images leaking content later. The overall impact is limited to configuration enforcement failure with moderate confidentiality, integrity, and availability impacts.

Mitigation Recommendations

Patches addressing this issue are available for Podman versions 5.8.6 and 6.0.0 at https://github.com/podman-container-tools/podman/commit/a38a9b7d20915c55e6f3c451101ae72d6da33742. If patching is not possible, workarounds include manually copying Quadlet files to the Quadlet directory or removing the destination file before running 'podman quadlet install' without the --replace option. Applying the official patches is the recommended remediation.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
redhat
Date Reserved
2026-08-13T13:07:39.303Z
Cvss Version
3.1
State
PUBLISHED
Vendor Advisory Urls
[{"url":"https://access.redhat.com/security/cve/CVE-2026-19730","vendor":"Red Hat"}]

Threat ID: 6a7e08efbf8831d5399b798e

Added to database: 08/13/2026, 18:11:59 UTC

Last enriched: 09/23/2026, 02:07:51 UTC

Last updated: 09/28/2026, 13:47:43 UTC

Views: 38

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses