diff --git a/RELEASE_NOTES.md b/RELEASE_NOTES.md index 5627f7fba9..1e9baac5d6 100644 --- a/RELEASE_NOTES.md +++ b/RELEASE_NOTES.md @@ -1,5 +1,11 @@ # Release Notes +## 5.8.8 +- This release addresses [CVE-2026-94603](https://github.com/podman-container-tools/podman/security/advisories/GHSA-2cvf-wqm6-wr9g), where a `podman run` on a checkpoint image (any image with the `io.podman.annotations.checkpoint.runtime.name` annotation) could disable all sandboxing, including sandboxing specified by the user, when the container was created. + +### Breaking Changes +- Removed support for checkpoint images in `podman run` due to serious security concerns with the different security models of running images and running checkpoints. Checkpoints ignore user-specified security configuration and are very difficult to run safely. + ## 5.8.7 ### Security - This release addresses ([CVE-2025-11395](https://github.com/podman-container-tools/container-libs/security/advisories/GHSA-3gcv-x57j-xqxv)), where importing images containing crafted layer tarballs with the `podman load` command, or importing volumes containing crafted symlinks with `podman volume import`, allows overwriting files on the host. diff --git a/version/rawversion/version.go b/version/rawversion/version.go index cf1c51554d..cec9401b34 100644 --- a/version/rawversion/version.go +++ b/version/rawversion/version.go @@ -4,4 +4,4 @@ package rawversion // // This indirection is needed to prevent semver packages from bloating // Quadlet's binary size. -const RawVersion = "5.8.8-dev" +const RawVersion = "5.8.8"