- This release addresses CVE-2026-94603, where a
podman runon a checkpoint image (any image with theio.podman.annotations.checkpoint.runtime.nameannotation) could disable all sandboxing, including sandboxing specified by the user, when the container was created.
Breaking Changes
- Removed support for checkpoint images in
podman rundue to serious security concerns with the different security models of running images and running checkpoints. Checkpoints ignore user-specified security configuration and are very difficult to run safely.