Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 0.7%top 51%

Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update

0
High
Published: 05/05/2026 (05/05/2026, 16:49:54 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Red Hat has issued a security advisory for Red Hat Hardened Images RPMs addressing vulnerabilities in busybox packages. The update includes fixes for CVE-2026-26157 and CVE-2026-26158 affecting busybox versions in Red Hat Hardened Images for aarch64 and x86_64 architectures. These vulnerabilities are classified under CWE-73. The advisory provides updated RPMs to mitigate these issues. No explicit patch version or fixed version is stated in the advisory content.

CVSS v3.1

Score 7.0high

Attack Vector
Local
Attack Complexity
High
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/31/2026, 00:37:24 UTC

Technical Analysis

This security advisory from Red Hat addresses two vulnerabilities identified as CVE-2026-26157 and CVE-2026-26158 in busybox packages included in Red Hat Hardened Images RPMs. The affected packages include busybox-1.37.0-7.2.hum1 variants for aarch64 and x86_64 architectures. The vulnerabilities are related to CWE-73, which involves improper handling of external control over file names or paths. The advisory references updated RPMs containing security fixes but does not specify fixed version numbers. The CVSS vector provided for CVE-2026-26157 indicates a high severity with local attack vector, high complexity, no privileges required, user interaction required, and impacts confidentiality, integrity, and availability.

Potential Impact

The vulnerabilities impact busybox packages used in Red Hat Hardened Images on aarch64 and x86_64 platforms. The CVSS vector for CVE-2026-26157 shows high impact on confidentiality, integrity, and availability, indicating that successful exploitation could lead to significant compromise of affected systems. No known exploits in the wild have been reported at this time.

Mitigation Recommendations

Red Hat has released updated busybox RPMs (version 1.37.0-7.2.hum1) for affected architectures to address these vulnerabilities. Users of Red Hat Hardened Images should apply these updates as provided by Red Hat to remediate the issues. Since this is an RPM update, following the standard Red Hat update procedures for these packages is recommended. Patch status is confirmed by the vendor advisory indicating the availability of fixed RPMs.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:13831
Cve Count
2
Additional Cves
["CVE-2026-26158"]
Cvss Version
3.1

Threat ID: 6a4049d427e9c7971982cae5

Added to database: 06/27/2026, 22:08:20 UTC

Last enriched: 07/31/2026, 00:37:24 UTC

Last updated: 07/31/2026, 19:22:58 UTC

Views: 33

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses