Red Hat disclosed and patched CVE-2026-39822, an Important vulnerability in Go's os.Root handling on Unix systems that can improperly follow a symbolic link outside the intended root boundary, enabling directory traversal. The flaw is triggered when the final path component is a symlink and the supplied path ends with a trailing slash, such as root.Open("symlink/"), and Red Hat said fixes were prepared across multiple Red Hat Enterprise Linux releases, including RHEL 8, RHEL 9, RHEL 10, and Extended Update Support variants.
Red Hat published July advisories covering affected container tooling, including RHSA-2026:38878 for podman on RHEL 9 and RHSA-2026:38493 and RHSA-2026:38494 for buildah on RHEL 9 and RHEL 10. The updates deliver patched packages including podman 5.8.2-5.el9_8 and buildah 1.43.1-4.el9_8 and 1.43.1-4.el10_2, with fixes released for multiple architectures and support channels such as x86_64, s390x, ppc64le, and aarch64.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Important advisory RHSA-2026:57361 for RHEL CoreOS 4 systems running OpenShift Container Platform 4.22.11. The update addresses CVE-2026-39822 as well as the CRI-O HOME-variable /etc/passwd injection bypass CVE-2026-15809 and Go MIME denial-of-service flaw CVE-2026-42504.
Red Hat issued Important advisory RHSA-2026:38878 for podman on Red Hat Enterprise Linux 9 to remediate CVE-2026-39822. The update released podman version 5.8.2-5.el9_8 for several RHEL 9 variants and architectures.
Red Hat issued Important advisory RHSA-2026:38494 for buildah on Red Hat Enterprise Linux 10 addressing CVE-2026-39822. The advisory released buildah version 1.43.1-4.el10_2 for multiple RHEL 10 support channels and architectures.
Red Hat issued Important advisory RHSA-2026:38493 for buildah on Red Hat Enterprise Linux 9 to fix CVE-2026-39822. The update shipped buildah version 1.43.1-4.el9_8 across multiple RHEL 9 variants and architectures.
The Go os.Root symlink-following directory traversal issue was recorded by OSIDB Bzimport in Bugzilla as issue 2498152. The entry describes a Unix flaw where a trailing slash on a symlink path can escape the intended root boundary.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
5 references tracked. Mallory keeps watching after this page renders.
tenable.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.