Podman 6.1.3 closes a sandbox bypass by removing checkpoint images from podman run
The security fix is deliberately breaking: checkpoint images can no longer override user-requested container isolation through the normal run path.
Podman 6.1.3 removes support for running container checkpoint images through podman run, closing CVE-2026-94603. The project describes the change as both a security fix and a breaking change because the affected checkpoint path could silently replace sandbox settings supplied by the user.
What changed
Podman added OCI distribution of container checkpoints in version 4.4.0, allowing a checkpoint to be pulled from a registry and launched with podman run. Podman identifies those artifacts through the io.podman.annotations.checkpoint.runtime.name image annotation.
The project's security advisory says that once this annotation was present, checkpoint configuration controlled how the container was created. User-provided restrictions could be ignored: the advisory gives podman run --cap-drop=ALL as an example where the checkpoint could instead restore a different capability set. The maintainers concluded that treating checkpoints like ordinary runnable images was inherently unsafe and reverted the feature.
Who it affects
Teams that pull images from registries and depend on command-line sandbox controls should treat the update as security-relevant. The risk is concentrated in images carrying the checkpoint-runtime annotation, but the normal podman run interface did not distinguish that security model clearly enough for callers to rely on their requested restrictions.
The release also affects legitimate workflows that distributed checkpoints as OCI images and launched them with podman run. Podman 6.1.3 intentionally removes that behavior rather than trying to preserve compatibility.
What to do
Users on the 6.1 line should update to 6.1.3 and test any checkpoint-transfer workflow against the removal. Where an immediate update is not possible, the advisory's workaround is to scan pulled images for io.podman.annotations.checkpoint.runtime.name and reject images carrying it. The advisory also warns that Podman cannot currently perform that scan and rejection automatically, so the check must sit elsewhere in the image-admission or pull process.
sources
- Podman v6.1.3 release notesgithub.com
- GHSA-2cvf-wqm6-wr9g security advisorygithub.com
comments · 0