From 59c16c10893489190bf545033bb32f9a4ebb2499 Mon Sep 17 00:00:00 2001 From: Matt Heon Date: Tue, 29 Sep 2026 09:04:38 -0400 Subject: [PATCH 1/2] Release notes for v5.8.8 Signed-off-by: Matt Heon --- RELEASE_NOTES.md | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/RELEASE_NOTES.md b/RELEASE_NOTES.md index 5627f7fba9f..1e9baac5d61 100644 --- a/RELEASE_NOTES.md +++ b/RELEASE_NOTES.md @@ -1,5 +1,11 @@ # Release Notes +## 5.8.8 +- This release addresses [CVE-2026-94603](https://github.com/podman-container-tools/podman/security/advisories/GHSA-2cvf-wqm6-wr9g), where a `podman run` on a checkpoint image (any image with the `io.podman.annotations.checkpoint.runtime.name` annotation) could disable all sandboxing, including sandboxing specified by the user, when the container was created. + +### Breaking Changes +- Removed support for checkpoint images in `podman run` due to serious security concerns with the different security models of running images and running checkpoints. Checkpoints ignore user-specified security configuration and are very difficult to run safely. + ## 5.8.7 ### Security - This release addresses ([CVE-2025-11395](https://github.com/podman-container-tools/container-libs/security/advisories/GHSA-3gcv-x57j-xqxv)), where importing images containing crafted layer tarballs with the `podman load` command, or importing volumes containing crafted symlinks with `podman volume import`, allows overwriting files on the host. From ee099ca84b6c99376cefa765c84bf2082628e336 Mon Sep 17 00:00:00 2001 From: Matt Heon Date: Tue, 29 Sep 2026 09:04:58 -0400 Subject: [PATCH 2/2] Bump to v5.8.8 Signed-off-by: Matt Heon --- version/rawversion/version.go | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/version/rawversion/version.go b/version/rawversion/version.go index cf1c51554d7..cec9401b349 100644 --- a/version/rawversion/version.go +++ b/version/rawversion/version.go @@ -4,4 +4,4 @@ package rawversion // // This indirection is needed to prevent semver packages from bloating // Quadlet's binary size. -const RawVersion = "5.8.8-dev" +const RawVersion = "5.8.8"