- Issued:
- 2026-07-09
- Updated:
- 2026-07-09
RHSA-2026:37385 - Important: rh-podman-desktop security advisory update
Synopsis
Important: rh-podman-desktop security advisory update
Type/Severity
Security Advisory Important
Topic
A security advisory update for rh-podman-desktop is now available for Red Hat Enterprise Linux 10.
Description
Red Hat build of Podman Desktop is a graphical tool for managing containers using Podman. It allows users to run, manage, and configure containers and container images using a desktop GUI.
Most notable CVE and Bug Fix(es) and Enhancement(s):
- Issues for CVE fix 1.1.1 (JIRA:RHDESK-595)
- Fix for RHDESK-529, RHDESK-530, RHDESK-531 - "fast-uri: Path traversal vulnerability allows bypass of security policies (CVE-2026-6321)"
- Fix for RHDESK-611 - "protobufjs: Arbitrary code execution due to unsafe expression generation from crafted protobuf descriptors (CVE-2026-44293)"
- Fix for RHDESK-640 - "fast-uri: URI authority bypass due to improper delimiter handling (CVE-2026-6322)"
Solution
Before applying this update, make sure all previously released errata relevant to your system have been applied.
For details on how to apply this update, refer to:
https://access.redhat.com/articles/11258
Affected Products
| Product | Version | Arch |
|---|---|---|
| Red Hat Enterprise Linux for x86_64 | 10 | x86_64 |
Updated Packages
- rh-podman-desktop-1.1.1-1.el10_2.src.rpm
- rh-podman-desktop-1.1.1-1.el10_2.x86_64.rpm
Fixes
CVEs
References
Additional information
- The Red Hat security contact is This content is not included.secalert@redhat.com. More contact details at Security Contacts and Procedures.
- Offline Security Data data is available for integration with other systems. See Offline Security Data API to get started.