Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 0.2%top 85%

Red Hat Security Advisory: glibc security update

0
Medium
Published: 07/21/2026 (07/21/2026, 15:25:35 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

This release of the Red Hat OpenShift distributed tracing platform (Tempo) provides security improvements. Breaking changes: * None Deprecations: * None Technology Preview features: * None Enhancements: * None Bug fixes: * Punycode labels are no longer processed incorrectly: Before this update, the golang.org/x/net/idna package incorrectly processed certain Punycode labels during internationalized domain name conversion. As a consequence, an attacker could craft a domain name that resolved to a different host than the one that was validated, which could lead to privilege escalation. With this update, Punycode labels are processed correctly. As a result, converted domain names match the validated input. For more information, see https://access.redhat.com/security/cve/cve-2026-39821. * The os.Root type no longer follows symbolic links outside of its root: Before this update, the Go os package did not correctly restrict some operations performed through an os.Root value. As a consequence, an attacker who controlled a symbolic link inside the root directory could traverse outside of it and access files elsewhere on the file system. With this update, operations on an os.Root value are correctly confined to the root directory. As a result, symbolic links can no longer be used to escape the root. For more information, see https://access.redhat.com/security/cve/cve-2026-39822. * The ungetwc function no longer mishandles specific wide character encodings: Before this update, the ungetwc function in the GNU C Library mishandled certain wide character encodings. As a consequence, an application could disclose information or terminate unexpectedly. With this update, the wide character encodings are handled correctly. As a result, the affected applications no longer disclose information or crash. For more information, see https://access.redhat.com/security/cve/cve-2026-5928. * TSIG record processing no longer writes outside the allocated buffer: Before this update, the DNS resolver in the GNU C Library did not correctly validate buffer boundaries when it processed TSIG records. As a consequence, a crafted TSIG record could trigger an out-of-bounds write and cause memory corruption. With this update, the buffer boundaries are validated correctly. As a result, TSIG record processing no longer writes outside the allocated buffer. For more information, see https://access.redhat.com/security/cve/cve-2026-5435. * Crafted DNS responses no longer cause a crash or an uninitialized memory read: Before this update, the DNS resolver in the GNU C Library did not correctly handle malformed responses. As a consequence, a crafted DNS response could cause an application to read uninitialized memory or terminate unexpectedly. With this update, malformed responses are handled correctly. As a result, the affected applications no longer crash or read uninitialized memory. For more information, see https://access.redhat.com/security/cve/cve-2026-6238. Known issues: * None

Affected software

Affected versions
=3.10.1Red HatRed Hat Enterprise LinuxRed Hat Enterprise Linux BaseOS (v. 8)Red Hat Enterprise Linux AppStream (v. 8)Red Hat Enterprise Linux CRB (v. 8)Red Hat Enterprise Linux AppStream (v. 9)Red Hat Enterprise Linux BaseOS (v. 9)Red Hat Enterprise Linux CodeReady Linux Builder (v. 9)Red Hat OpenShift distributed tracingRed Hat OpenShift distributed tracing 3.10.0amd64registry.redhat.io/rhosdt/tempo-operator-bundle@sha256:40c77256530f670a5951bb76fd98780b04756f5bc533c885dcd227a0155ad303_amd64Red Hat OpenShift distributed tracing 3.10.1

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/16/2026, 16:23:09 UTC

Technical Analysis

The glibc packages provide essential C libraries and services for Linux systems. Three security flaws have been fixed: CVE-2026-5928 involves information disclosure or denial of service through the ungetwc function when processing specific wide character encodings; CVE-2026-5435 is an out-of-bounds write vulnerability triggered by TSIG record processing; CVE-2026-6238 causes application crashes or uninitialized memory reads via crafted DNS responses. These vulnerabilities could impact system stability and confidentiality. Red Hat has issued security advisories RHSA-2026:42733 and RHSA-2026:42952 detailing patches for Red Hat Enterprise Linux versions 8 and 9 respectively. The advisories provide updated package versions and instructions for applying the fixes.

Potential Impact

The vulnerabilities could lead to information disclosure, denial of service, application crashes, or uninitialized memory reads on affected systems. Since glibc is a core system library, exploitation could affect multiple programs relying on these libraries. The severity is rated as moderate by Red Hat Product Security. There are no known exploits in the wild at this time.

Mitigation Recommendations

Red Hat has released official security updates for glibc in Red Hat Enterprise Linux 8 and 9 to address these vulnerabilities. Users should apply the updates as detailed in Red Hat advisories RHSA-2026:42733 and RHSA-2026:42952. The advisories include package names and instructions for remediation. No additional mitigation steps are indicated beyond applying the official patches.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:42733
Cve Count
3
Additional Cves
["CVE-2026-5928","CVE-2026-6238"]
Cvss Version
null

Threat ID: 6a5fd0931010f89cc2198ffd

Added to database: 07/21/2026, 20:03:31 UTC

Last enriched: 08/16/2026, 16:23:09 UTC

Last updated: 09/04/2026, 22:52:13 UTC

Views: 90

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses