Security
- This release addresses (CVE-2025-11395), where importing images containing crafted layer tarballs with the
podman loadcommand, or importing volumes containing crafted symlinks withpodman volume import, allows overwriting files on the host. - This release also addresses CVE-2026-79699 and CVE-2026-79705, though we do not believe these CVEs are exploitable through the Podman command line.
Misc
- Updated Buildah to v1.43.4
- Updated Common to v0.67.2
- Updated Image to v5.39.3
- Updated Storage to v1.62.1