Skip to main content
EPSS 0.2%top 87%

Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update

0
Low
Published: 09/02/2026 (09/02/2026, 17:47:24 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

This advisory addresses a low severity vulnerability in Red Hat Hardened Images RPMs, specifically related to Ruby 3.4 packages. The update includes multiple RPM packages with bug fixes and enhancements. The vulnerability is identified as CWE-354 (Improper Control of Generation of Code). The advisory references Ubuntu security notices for OpenSSL vulnerabilities but does not provide detailed exploit or impact information specific to the Ruby packages. No known exploits are reported in the wild.

Affected software

Ubuntu:Pro:16.04:LTSmore threats →ghsa
nodejs
pkg:deb/ubuntu/nodejs?arch=source&distro=esm-apps/xenial
Affected versions
=0.10.25~dfsg2-2ubuntu1=4.2.2~dfsg-1=4.2.3~dfsg-1=4.2.4~dfsg-1ubuntu1=4.2.4~dfsg-2=4.2.6~dfsg-1ubuntu1=4.2.6~dfsg-1ubuntu4=4.2.6~dfsg-1ubuntu4.1=4.2.6~dfsg-1ubuntu4.2=4.2.6~dfsg-1ubuntu4.2+esm1=4.2.6~dfsg-1ubuntu4.2+esm2=4.2.6~dfsg-1ubuntu4.2+esm3
Ubuntu:Pro:18.04:LTSmore threats →ghsa
nodejs
pkg:deb/ubuntu/nodejs?arch=source&distro=esm-apps/bionic
Affected versions
=6.11.4~dfsg-1ubuntu1=6.11.4~dfsg-1ubuntu2=6.12.0~dfsg-1ubuntu1=6.12.0~dfsg-2ubuntu1=6.12.0~dfsg-2ubuntu2=8.10.0~dfsg-2=8.10.0~dfsg-2ubuntu0.2=8.10.0~dfsg-2ubuntu0.3=8.10.0~dfsg-2ubuntu0.4=8.10.0~dfsg-2ubuntu0.4+esm1=8.10.0~dfsg-2ubuntu0.4+esm2=8.10.0~dfsg-2ubuntu0.4+esm3=8.10.0~dfsg-2ubuntu0.4+esm4=8.10.0~dfsg-2ubuntu0.4+esm5=8.10.0~dfsg-2ubuntu0.4+esm6
Ubuntu:22.04:LTSmore threats →ghsa
openssl
pkg:deb/ubuntu/openssl?arch=source&distro=jammy
Affected versions
=1.1.1l-1ubuntu1=3.0.0-1ubuntu1=3.0.1-0ubuntu1=3.0.2-0ubuntu1=3.0.2-0ubuntu1.1=3.0.2-0ubuntu1.2=3.0.2-0ubuntu1.4=3.0.2-0ubuntu1.5=3.0.2-0ubuntu1.6=3.0.2-0ubuntu1.7=3.0.2-0ubuntu1.8=3.0.2-0ubuntu1.9=3.0.2-0ubuntu1.10=3.0.2-0ubuntu1.12=3.0.2-0ubuntu1.13=3.0.2-0ubuntu1.14=3.0.2-0ubuntu1.15=3.0.2-0ubuntu1.16=3.0.2-0ubuntu1.17=3.0.2-0ubuntu1.18=3.0.2-0ubuntu1.19=3.0.2-0ubuntu1.20=3.0.2-0ubuntu1.21=3.0.2-0ubuntu1.23=3.0.2-0ubuntu1.25=3.0.2-0ubuntu1.26
Ubuntu:Pro:FIPS-preview:22.04:LTSmore threats →ghsa
openssl
pkg:deb/ubuntu/openssl?arch=source&distro=fips-preview/jammy
Affected versions
=3.0.2-0ubuntu1.10+Fips1=3.0.2-0ubuntu1.12+Fips1
Ubuntu:Pro:FIPS-preview:22.04:LTSmore threats →ghsa
openssl-fips
pkg:deb/ubuntu/openssl-fips?arch=source&distro=fips-preview/jammy
Affected versions
=3.0.5-0ubuntu0.1+Fips2.1
Ubuntu:Pro:FIPS-updates:22.04:LTSmore threats →ghsa
openssl
pkg:deb/ubuntu/openssl?arch=source&distro=fips-updates/jammy
Affected versions
=3.0.2-0ubuntu1.10+Fips1=3.0.2-0ubuntu1.12+Fips1=3.0.2-0ubuntu1.14+Fips1=3.0.2-0ubuntu1.15+Fips1=3.0.2-0ubuntu1.16+Fips1=3.0.2-0ubuntu1.17+Fips1=3.0.2-0ubuntu1.18+Fips1=3.0.2-0ubuntu1.19+Fips1=3.0.2-0ubuntu1.20+Fips1=3.0.2-0ubuntu1.21+Fips1=3.0.2-0ubuntu1.23+Fips1=3.0.2-0ubuntu1.25+Fips1=3.0.2-0ubuntu1.26+Fips1
Ubuntu:Pro:FIPS-updates:22.04:LTSmore threats →ghsa
openssl-fips
pkg:deb/ubuntu/openssl-fips?arch=source&distro=fips-updates/jammy
Affected versions
=3.0.5-0ubuntu0.1+Fips2.1=3.0.5-0ubuntu0.2+Fips1
Ubuntu:24.04:LTSmore threats →ghsa
edk2
pkg:deb/ubuntu/edk2?arch=source&distro=noble
Affected versions
=2023.05-2=2023.11-2=2023.11-3=2023.11-4=2023.11-5=2023.11-6=2023.11-8=2024.02-1=2024.02-2=2024.02-2ubuntu0.1=2024.02-2ubuntu0.3=2024.02-2ubuntu0.4=2024.02-2ubuntu0.5=2024.02-2ubuntu0.6=2024.02-2ubuntu0.7=2024.02-2ubuntu0.8=2024.02-2ubuntu0.9
Ubuntu:24.04:LTSmore threats →ghsa
openssl
pkg:deb/ubuntu/openssl?arch=source&distro=noble
Affected versions
=3.0.10-1ubuntu2=3.0.10-1ubuntu2.1=3.0.10-1ubuntu3=3.0.10-1ubuntu4=3.0.13-0ubuntu2=3.0.13-0ubuntu3=3.0.13-0ubuntu3.1=3.0.13-0ubuntu3.2=3.0.13-0ubuntu3.3=3.0.13-0ubuntu3.4=3.0.13-0ubuntu3.5=3.0.13-0ubuntu3.6=3.0.13-0ubuntu3.7=3.0.13-0ubuntu3.9=3.0.13-0ubuntu3.11=3.0.13-0ubuntu3.12
Ubuntu:Pro:FIPS-updates:24.04:LTSmore threats →ghsa
openssl-fips
pkg:deb/ubuntu/openssl-fips?arch=source&distro=fips-updates/noble
Affected versions
=3.0.13-0ubuntu3+Fips1=3.0.13-0ubuntu3.6+Fips1
Ubuntu:26.04:LTSmore threats →ghsa
edk2
pkg:deb/ubuntu/edk2?arch=source&distro=resolute
Affected versions
=2025.02-8ubuntu3=2025.11-3ubuntu6=2025.11-3ubuntu7
Ubuntu:26.04:LTSmore threats →ghsa
openssl
pkg:deb/ubuntu/openssl?arch=source&distro=resolute
Affected versions
=3.5.3-1ubuntu2=3.5.5-1ubuntu1=3.5.5-1ubuntu3=3.5.5-1ubuntu3.2=3.5.5-1ubuntu3.3

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/25/2026, 04:51:40 UTC

Technical Analysis

The Red Hat Security Advisory details an update to Ruby 3.4 RPM packages in Red Hat Hardened Images, including bug fixes and enhancements. The vulnerability is categorized under CWE-354. The advisory lists affected versions explicitly, including various Ubuntu package versions and Red Hat Hardened Images versions. The vendor advisory references multiple OpenSSL vulnerabilities affecting Ubuntu 26.04 LTS but does not link these directly to the Ruby packages. No active exploitation is reported.

Potential Impact

The vulnerability is rated low severity and is related to improper control of code generation (CWE-354). There are no known exploits in the wild. The impact is limited to potential issues in the Ruby 3.4 packages included in Red Hat Hardened Images. No direct impact details such as remote code execution or privilege escalation are provided.

Mitigation Recommendations

A fix is available through the updated RPM packages listed in the advisory. Users should apply the provided updates to Ruby 3.4 packages as per the Red Hat Security Advisory. No additional mitigation steps are indicated or required beyond applying the official updates.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
UBUNTU-CVE-2026-75803
Osv Schema Version
1.7.0
Ecosystems
["Ubuntu:Pro:16.04:LTS","Ubuntu:Pro:18.04:LTS","Ubuntu:22.04:LTS","Ubuntu:Pro:FIPS-preview:22.04:LTS","Ubuntu:Pro:FIPS-updates:22.04:LTS","Ubuntu:24.04:LTS","Ubuntu:Pro:FIPS-updates:24.04:LTS","Ubuntu:26.04:LTS"]

Threat ID: 6a882c05acd9273b4902e1dd

Added to database: 08/21/2026, 10:44:21 UTC

Last enriched: 09/25/2026, 04:51:40 UTC

Last updated: 10/06/2026, 06:48:20 UTC

Views: 140

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses