Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
Description
This advisory addresses a low severity vulnerability in Red Hat Hardened Images RPMs, specifically related to Ruby 3.4 packages. The update includes multiple RPM packages with bug fixes and enhancements. The vulnerability is identified as CWE-354 (Improper Control of Generation of Code). The advisory references Ubuntu security notices for OpenSSL vulnerabilities but does not provide detailed exploit or impact information specific to the Ruby packages. No known exploits are reported in the wild.
Affected software
pkg:deb/ubuntu/nodejs?arch=source&distro=esm-apps/xenialpkg:deb/ubuntu/nodejs?arch=source&distro=esm-apps/bionicpkg:deb/ubuntu/openssl?arch=source&distro=jammypkg:deb/ubuntu/openssl?arch=source&distro=fips-preview/jammypkg:deb/ubuntu/openssl-fips?arch=source&distro=fips-preview/jammypkg:deb/ubuntu/openssl?arch=source&distro=fips-updates/jammypkg:deb/ubuntu/openssl-fips?arch=source&distro=fips-updates/jammypkg:deb/ubuntu/edk2?arch=source&distro=noblepkg:deb/ubuntu/openssl?arch=source&distro=noblepkg:deb/ubuntu/openssl-fips?arch=source&distro=fips-updates/noblepkg:deb/ubuntu/edk2?arch=source&distro=resolutepkg:deb/ubuntu/openssl?arch=source&distro=resoluteRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Red Hat Security Advisory details an update to Ruby 3.4 RPM packages in Red Hat Hardened Images, including bug fixes and enhancements. The vulnerability is categorized under CWE-354. The advisory lists affected versions explicitly, including various Ubuntu package versions and Red Hat Hardened Images versions. The vendor advisory references multiple OpenSSL vulnerabilities affecting Ubuntu 26.04 LTS but does not link these directly to the Ruby packages. No active exploitation is reported.
Potential Impact
The vulnerability is rated low severity and is related to improper control of code generation (CWE-354). There are no known exploits in the wild. The impact is limited to potential issues in the Ruby 3.4 packages included in Red Hat Hardened Images. No direct impact details such as remote code execution or privilege escalation are provided.
Mitigation Recommendations
A fix is available through the updated RPM packages listed in the advisory. Users should apply the provided updates to Ruby 3.4 packages as per the Red Hat Security Advisory. No additional mitigation steps are indicated or required beyond applying the official updates.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2026-75803
- Osv Schema Version
- 1.7.0
- Ecosystems
- ["Ubuntu:Pro:16.04:LTS","Ubuntu:Pro:18.04:LTS","Ubuntu:22.04:LTS","Ubuntu:Pro:FIPS-preview:22.04:LTS","Ubuntu:Pro:FIPS-updates:22.04:LTS","Ubuntu:24.04:LTS","Ubuntu:Pro:FIPS-updates:24.04:LTS","Ubuntu:26.04:LTS"]
Threat ID: 6a882c05acd9273b4902e1dd
Added to database: 08/21/2026, 10:44:21 UTC
Last enriched: 09/25/2026, 04:51:40 UTC
Last updated: 10/06/2026, 06:48:20 UTC
Views: 140
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.