Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update
This update includes the following RPMs: dotnet8.0: * aspnetcore-runtime-8.0-8.0.28-1.2.hum1 (aarch64, x86_64) * aspnetcore-runtime-dbg-8.0-8.0.28-1.2.hum1 (aarch64, x86_64) * aspnetcore-targeting-pack-8.0-8.0.28-1.2.hum1 (aarch64, x86_64) * dotnet-apphost-pack-8.0-8.0.28-1.2.hum1 (aarch64, x86_64) * dotnet-hostfxr-8.0-8.0.28-1.2.hum1 (aarch64, x86_64) * dotnet-runtime-8.0-8.0.28-1.2.hum1 (aarch64, x86_64) * dotnet-runtime-dbg-8.0-8.0.28-1.2.hum1 (aarch64, x86_64) * dotnet-sdk-8.0-8.0.128-1.2.hum1 (aarch64, x86_64) * dotnet-sdk-8.0-source-built-artifacts-8.0.128-1.2.hum1 (aarch64, x86_64) * dotnet-sdk-dbg-8.0-8.0.128-1.2.hum1 (aarch64, x86_64) * dotnet-targeting-pack-8.0-8.0.28-1.2.hum1 (aarch64, x86_64) * dotnet-templates-8.0-8.0.128-1.2.hum1 (aarch64, x86_64) * dotnet8.0-8.0.128-1.2.hum1.src (src) Security Fix(es): dotnet8.0: * CVE-2026-53486
AI Analysis
Technical Summary
CVE-2026-53486 is a vulnerability in the decompress npm package version 4.2.1 or earlier, used in Red Hat Hardened Images (dotnet8.0) and other Red Hat components. The flaw arises from insufficient path containment checks and improper handling of hardlink and symlink entries during archive extraction, allowing crafted archives to write or read files outside the intended directory. This can lead to unauthorized file access or modification, affecting confidentiality and integrity. Red Hat rates this issue as Important with a CVSS score of 8.1, reflecting that extraction is performed on locally supplied archives requiring user interaction. The original decompress package is unmaintained and has no upstream fix; the maintained fork @xhmikosr/decompress has fixes in versions 10.2.1 and 11.1.3 but is not used by Red Hat components. Red Hat has released updated RPMs for dotnet8.0 packages to address this vulnerability.
Potential Impact
The vulnerability allows an attacker who can supply a crafted archive to cause extraction processes to create or overwrite files and links outside the intended directory. This can lead to unauthorized reading or writing of files, potentially exposing sensitive data or modifying critical files. The impact affects confidentiality and integrity but not availability. Because extraction is performed on locally supplied or build-time archives rather than arbitrary network input, exploitation requires user interaction. The vulnerability could allow bypassing security mechanisms if critical files are overwritten or read.
Mitigation Recommendations
Red Hat has released updated RPM packages for dotnet8.0 components that fix this vulnerability. Users should apply these updates as provided by Red Hat Hardened Images RPMs. Since the original decompress package is unmaintained and no upstream fix exists, Red Hat components do not use the maintained fork with the fix. As a mitigation, only extract archives from trusted sources, run extraction as a non-root user to prevent privileged file creation, and verify that symlinks or hardlinks created during extraction resolve within the intended output directory.
Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update
Description
This update includes the following RPMs: dotnet8.0: * aspnetcore-runtime-8.0-8.0.28-1.2.hum1 (aarch64, x86_64) * aspnetcore-runtime-dbg-8.0-8.0.28-1.2.hum1 (aarch64, x86_64) * aspnetcore-targeting-pack-8.0-8.0.28-1.2.hum1 (aarch64, x86_64) * dotnet-apphost-pack-8.0-8.0.28-1.2.hum1 (aarch64, x86_64) * dotnet-hostfxr-8.0-8.0.28-1.2.hum1 (aarch64, x86_64) * dotnet-runtime-8.0-8.0.28-1.2.hum1 (aarch64, x86_64) * dotnet-runtime-dbg-8.0-8.0.28-1.2.hum1 (aarch64, x86_64) * dotnet-sdk-8.0-8.0.128-1.2.hum1 (aarch64, x86_64) * dotnet-sdk-8.0-source-built-artifacts-8.0.128-1.2.hum1 (aarch64, x86_64) * dotnet-sdk-dbg-8.0-8.0.128-1.2.hum1 (aarch64, x86_64) * dotnet-targeting-pack-8.0-8.0.28-1.2.hum1 (aarch64, x86_64) * dotnet-templates-8.0-8.0.128-1.2.hum1 (aarch64, x86_64) * dotnet8.0-8.0.128-1.2.hum1.src (src) Security Fix(es): dotnet8.0: * CVE-2026-53486
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-53486 is a vulnerability in the decompress npm package version 4.2.1 or earlier, used in Red Hat Hardened Images (dotnet8.0) and other Red Hat components. The flaw arises from insufficient path containment checks and improper handling of hardlink and symlink entries during archive extraction, allowing crafted archives to write or read files outside the intended directory. This can lead to unauthorized file access or modification, affecting confidentiality and integrity. Red Hat rates this issue as Important with a CVSS score of 8.1, reflecting that extraction is performed on locally supplied archives requiring user interaction. The original decompress package is unmaintained and has no upstream fix; the maintained fork @xhmikosr/decompress has fixes in versions 10.2.1 and 11.1.3 but is not used by Red Hat components. Red Hat has released updated RPMs for dotnet8.0 packages to address this vulnerability.
Potential Impact
The vulnerability allows an attacker who can supply a crafted archive to cause extraction processes to create or overwrite files and links outside the intended directory. This can lead to unauthorized reading or writing of files, potentially exposing sensitive data or modifying critical files. The impact affects confidentiality and integrity but not availability. Because extraction is performed on locally supplied or build-time archives rather than arbitrary network input, exploitation requires user interaction. The vulnerability could allow bypassing security mechanisms if critical files are overwritten or read.
Mitigation Recommendations
Red Hat has released updated RPM packages for dotnet8.0 components that fix this vulnerability. Users should apply these updates as provided by Red Hat Hardened Images RPMs. Since the original decompress package is unmaintained and no upstream fix exists, Red Hat components do not use the maintained fork with the fix. As a mitigation, only extract archives from trusted sources, run extraction as a non-root user to prevent privileged file creation, and verify that symlinks or hardlinks created during extraction resolve within the intended output directory.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-mp2f-45pm-3cg9
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-53486"]
- Ecosystems
- ["npm"]
- Database Specific Severity
- CRITICAL
- Cvss Version
- 3.1
Threat ID: 6a4c340627e9c797195f6754
Added to database: 07/06/2026, 23:02:30 UTC
Last enriched: 08/16/2026, 15:40:59 UTC
Last updated: 09/09/2026, 13:09:35 UTC
Views: 451
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.