Skip to content

Releases: podman-container-tools/podman

v5.8.7

Choose a tag to compare

@github-actions github-actions released this 16 Sep 18:13
v5.8.7
c593b67

Security

  • This release addresses (CVE-2025-11395), where importing images containing crafted layer tarballs with the podman load command, or importing volumes containing crafted symlinks with podman volume import, allows overwriting files on the host.
  • This release also addresses CVE-2026-79699 and CVE-2026-79705, though we do not believe these CVEs are exploitable through the Podman command line.

Misc

  • Updated Buildah to v1.43.4
  • Updated Common to v0.67.2
  • Updated Image to v5.39.3
  • Updated Storage to v1.62.1

v6.1.2

Choose a tag to compare

@github-actions github-actions released this 16 Sep 00:07
v6.1.2
04f3aa4

Security

  • This release addresses (CVE-2025-11395), where importing images containing crafted layer tarballs with the podman load command, or importing volumes containing crafted symlinks with podman volume import, allows overwriting files on the host.
  • This release also addresses CVE-2026-79699 and CVE-2026-79705, though we do not believe these CVEs are exploitable through the Podman command line.

Misc

  • Updated Buildah to v1.45.1
  • Updated Common to v0.69.2
  • Updated Image to v5.41.2
  • Updated Storage to v1.64.1

v6.1.1

Choose a tag to compare

@github-actions github-actions released this 02 Sep 16:35
v6.1.1
8303f2e

Security

  • This release addresses CVE-2026-17106, where a crafted tar archive could write outside the extraction directory through the use of malicious links (GHSA-hfg8-hc9c-6c3h).

Bugfixes

  • Fixed broken rootlessport bind behavior with -p 0.0.0.0:... -p [::]:... which failed instead of binding both v4 and v6 separately. Podman Machine on WSL should now correctly forward ports again by binding separate IPv4 and IPv6 sockets to make the WSL forwarder logic work again (#29377).

v5.8.6

Choose a tag to compare

@github-actions github-actions released this 13 Aug 21:11
v5.8.6
a859fc6

Security

  • This release addressed CVE-2026-19730 where the podman quadlet install --replace command did not truncate the file being replaced, meaning replacing a longer file with a shorter one would result in content from the original file incorrectly being retained.

v6.1.0

Choose a tag to compare

@github-actions github-actions released this 12 Aug 20:12
v6.1.0
cade97a

Features

  • A new command has been added, podman volume rename, to allow renaming volumes. Volumes created using volume drivers and volumes that are currently used by a container cannot be renamed (#28189).
  • A new command has been added, podman machine restart, to allow easy restart of VMs managed by podman machine (#28366).
  • The podman network rm command now includes a new option, --ignore, which suppresses errors when attempting to remove networks that do not exist (#28363).
  • The podman manifest push command now includes two new options, --retry and --retry-delay, which allow pushes to be automatically retried on failure (#28590).
  • Quadlet .container units now support a new key, ImageVolume=, to configure how volumes from images are handled (#28875).
  • The podman generate kube command now includes support for generating container healthchecks as a livenessProbe (#22095).
  • A new option, force_port_listen, has been added to containers.conf. This is required to be set when running Podman on WSL to support port forwarding from the Windows host. It is automatically set on newly-created podman machine VMs on Windows using the WSL provider.

Changes

  • The podman info command now includes free memory available on the host (in addition to used memory and total memory) (#29116).
  • The Pesto rootless port forwarding tool now supports IPv6 port forwarding with source IP preservation.

Bugfixes

  • Fixed a bug where the remote Podman client could hang on some operations when connecting to a remote Podman service over SSH (#28453).
  • Fixed a bug where the podman image scp command could not be used with usernames containing an @ character (#27655).
  • Fixed a bug where the podman kube play command did not properly validate requested hostPort bindings, allowing the creation of containers with duplicated host ports which would never be able to start at the same time (#26622).
  • Fixed a bug where podman machine VMs on Windows created using the hyperv provider would sometimes not properly start due to a race conditioning setting up volume mounts.
  • Fixed a bug where podman machine VMs on Mac where machines could be left in an inconsistent state if the podman machine start command was interrupted by a signal.
  • Fixed a bug where creating a container on a podman machine VM on Mac that attempted to bind to a port number number 1024 would return a nonsensical error message; a clear error explaining that privileged ports cannot be bound is now returned.
  • Fixed a bug where the podman quadlet list and podman quadlet rm commands did not function properly with uninstantiated template Quadlets.
  • Fixed a bug where the podman quadlet install command would occasionally fail to install a Quadlet if non-quadlet files were specified.
  • Fixed a bug where the podman quadlet install command would not refuse to install Quadlets including non-quadlet files if the --application option was not specified.
  • Fixed a bug where healthcheck logs could be corrupted, preventing proper healthcheck operation, if a healthcheck was killed midway through writing the file.
  • Fixed a bug where the podman volume prune --all command incorrectly discarded label filters, causing podman volume prune --all --filter label=foo to prune all volumes, not just those with the foo label.
  • Fixed a bug where the podman events --format=json command would print null instead of an error when the server sent an event that could not be decoded.
  • Fixed a bug where a race condition could cause Quadlet to generate corrupt systemd units (#29004).
  • Fixed a bug where the podman inspect command on a container with a single-element command (e.g. podman run fedora bash) would include the command in both Path and Args, when it should only have been included in Path (#29155).
  • Fixed a bug where the --format option to podman inspect on containers did not properly support some format specifiers supported by Docker (e.g. {{.HostIp}} did not work, but {{.HostIP}} did) (#29164).
  • Fixed a bug where the Quadlet generator would not write error messages to STDERR but only to /dev/kmsg, meaning that errors were not visible from systemd-analyze --generators verify and other tooling invoking the systemd generator directly.
  • Fixed a bug where containers which failed to start would, in some circumstances, not properly clean up, resulting in improper behavior (#26143).
  • Fixed a bug where the podman kube generate command would improperly generate warning messages only applicable when running as a rootless user on an SELinux enabled system when not running in that configuration (#17743).

API

  • Fixed a bug where the Compat and Libpod Create endpoint for Exec Sessions (/containers/$CID/exec) did not honor the ConsoleSize parameter in the exec config.
  • The Compat API has seen further changes to improve support for the Docker v1.44 API, including the deprecation of several fields removed in that release.
  • Preparations have begun to implement support for the v1.45 API.

Misc

  • Updated Buildah to v1.45.0
  • Updated the image library to v5.41.1
  • Updated the storage library to v1.64.0
  • Updated the common library to v0.69.1

v6.1.0-RC1

v6.1.0-RC1 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 31 Jul 18:07
v6.1.0-rc1
319d0cf

Features

  • A new command has been added, podman volume rename, to allow renaming volumes. Volumes created using volume drivers and volumes that are currently used by a container cannot be renamed (#28189).
  • A new command has been added, podman machine restart, to allow easy restart of VMs managed by podman machine (#28366).
  • The podman network rm command now includes a new option, --ignore, which suppresses errors when attempting to remove networks that do not exist (#28363).
  • The podman manifest push command now includes two new options, --retry and --retry-delay, which allow pushes to be automatically retried on failure (#28590).
  • Quadlet .container units now support a new key, ImageVolume=, to configure how volumes from images are handled (#28875).
  • The podman generate kube command now includes support for generating container healthchecks as a livenessProbe (#22095).

Changes

  • The podman info command now includes free memory available on the host (in addition to used memory and total memory) (#29116).
  • The Pesto rootless port forwarding tool now supports IPv6 port forwarding with source IP preservation.

Bugfixes

  • Fixed a bug where the remote Podman client could hang on some operations when connecting to a remote Podman service over SSH (#28453).
  • Fixed a bug where the podman image scp command could not be used with usernames containing an @ character (#27655).
  • Fixed a bug where the podman kube play command did not properly validate requested hostPort bindings, allowing the creation of containers with duplicated host ports which would never be able to start at the same time (#26622).
  • Fixed a bug where podman machine VMs on Windows created using the hyperv provider would sometimes not properly start due to a race conditioning setting up volume mounts.
  • Fixed a bug where podman machine VMs on Mac where machines could be left in an inconsistent state if the podman machine start command was interrupted by a signal.
  • Fixed a bug where creating a container on a podman machine VM on Mac that attempted to bind to a port number number 1024 would return a nonsensical error message; a clear error explaining that privileged ports cannot be bound is now returned.
  • Fixed a bug where the podman quadlet list and podman quadlet rm commands did not function properly with uninstantiated template Quadlets.
  • Fixed a bug where the podman quadlet install command would occasionally fail to install a Quadlet if non-quadlet files were specified.
  • Fixed a bug where the podman quadlet install command would not refuse to install Quadlets including non-quadlet files if the --application option was not specified.
  • Fixed a bug where healthcheck logs could be corrupted, preventing proper healthcheck operation, if a healthcheck was killed midway through writing the file.
  • Fixed a bug where the podman volume prune --all command incorrectly discarded label filters, causing podman volume prune --all --filter label=foo to prune all volumes, not just those with the foo label.
  • Fixed a bug where the podman events --format=json command would print null instead of an error when the server sent an event that could not be decoded.
  • Fixed a bug where a race condition could cause Quadlet to generate corrupt systemd units (#29004).
  • Fixed a bug where the podman inspect command on a container with a single-element command (e.g. podman run fedora bash) would include the command in both Path and Args, when it should only have been included in Path (#29155).
  • Fixed a bug where the --format option to podman inspect on containers did not properly support some format specifiers supported by Docker (e.g. {{.HostIp}} did not work, but {{.HostIP}} did) (#29164).
  • Fixed a bug where the Quadlet generator would not write error messages to STDERR but only to /dev/kmsg, meaning that errors were not visible from systemd-analyze --generators verify and other tooling invoking the systemd generator directly.
  • Fixed a bug where containers which failed to start would, in some circumstances, not properly clean up, resulting in improper behavior (#26143).
  • Fixed a bug where the podman kube generate command would improperly generate warning messages only applicable when running as a rootless user on an SELinux enabled system when not running in that configuration (#17743).

API

  • Fixed a bug where the Compat and Libpod Create endpoint for Exec Sessions (/containers/$CID/exec) did not honor the ConsoleSize parameter in the exec config.
  • The Compat API has seen further changes to improve support for the Docker v1.44 API, including the deprecation of several fields removed in that release.
  • Preparations have begun to implement support for the v1.45 API.

Misc

  • Updated Buildah to v1.45.0
  • Updated the image library to v5.41.0
  • Updated the storage library to v1.64.0
  • Updated the common library to v0.69.0

v6.0.2

Choose a tag to compare

@github-actions github-actions released this 22 Jul 03:02
v6.0.2
b28edb9

Bugfixes

  • Fixed a bug where podman machine VMs created by the WSL provider on Windows were not properly cleaned up if the podman machine init command failed (#27036).
  • Fixed a bug where the Windows installer for Podman would, when installing for all users, incorrectly modify the path of only the user installing Podman (#29160).
  • Fixed a bug where the remote Podman client would throw errors when run on a Linux system that was not using Cgroups v2 (#29241).

Misc

  • Updated Buildah to v1.44.1

v6.0.1

Choose a tag to compare

@github-actions github-actions released this 08 Jul 20:15
v6.0.1
4cabbe6

Bugfixes

  • Fixed a bug where Podman Machine VMs on Mac using the libkrun provider could be regularly turned off by a port-scanning process on the host unintentionally commanding the VM to shut down.
  • Fixed a bug where the podman machine init command would fail on Windows hosts when using the hyperv provider when WSL was not installed (#29053).
  • Fixed a bug where the podman machine init command would fail on Windows hosts when using the wsl provider when the user was a Hyper-V admin but Hyper-V is disabled (#29138).
  • Fixed a bug where error messages from the OCI runtime were sometimes not displayed when --log-level=debug was passed to Podman.
  • Fixed a bug where the podman machine os upgrade command did not function properly (#29085).
  • Fixed a bug where the default image used by podman machine was not being properly cached (#29090).
  • Fixed a bug where rootful Podman Machine VMs on Windows using the wsl provider would fail to start (#29003).
  • Fixed a bug where commands that did not support the --replace option would incorrectly suggest using that option in error messages (#24537).
  • Fixed a bug where the Pesto rootless port forwarding tool (enabled by rootless_port_forwarder=pasta) did not properly clean up rules on container restart and network reload, causing failures to forward traffic (#29032).

v5.8.5

Choose a tag to compare

@github-actions github-actions released this 08 Jul 18:46
v5.8.5
6d48b6f

Bugfixes

  • Fixed a bug where Podman Machine VMs on Mac using the libkrun provider could be regularly turned off by a port-scanning process on the host unintentionally commanding the VM to shut down.

v5.8.4

Choose a tag to compare

@github-actions github-actions released this 26 Jun 15:37
v5.8.4

Security

  • This release addresses CVE-2026-57231, where a malicious image using malformed Env entries could cause host environment variables to leak into containers run based on the image, including the ability to use the * glob operator to leak large numbers of environment variables without knowing their exact names (GHSA-4hq8-gpf5-8p68).
  • The golang.org/x/crypto library has been updated to v0.53.0, addressing CVE-2026-39830 and CVE-2026-42508.

Bugfixes

  • Fixed a bug where the remote Podman client's podman save command would fail on Linux when using the -f oci-dir or -f docker-dir arguments.