Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
This update includes the following RPMs: gnutls: * gnutls-3.8.13-1.hum1 (aarch64, x86_64) * gnutls-c++-3.8.13-1.hum1 (aarch64, x86_64) * gnutls-dane-3.8.13-1.hum1 (aarch64, x86_64) * gnutls-devel-3.8.13-1.hum1 (aarch64, x86_64) * gnutls-fips-3.8.13-1.hum1 (aarch64, x86_64) * gnutls-utils-3.8.13-1.hum1 (aarch64, x86_64) * mingw32-gnutls-3.8.13-1.hum1 (noarch) * mingw64-gnutls-3.8.13-1.hum1 (noarch) * gnutls-3.8.13-1.hum1.src (src)
AI Analysis
Technical Summary
This security advisory from Red Hat addresses multiple vulnerabilities affecting Red Hat Update Infrastructure 5.2 container images, which are based on the latest RHUI RPM packages and ubi9 or ubi9-init base images. Among the referenced CVEs is CVE-2026-28390, a moderate severity denial-of-service vulnerability in OpenSSL. The flaw occurs during processing of Cryptographic Message Syntax (CMS) EnvelopedData messages with RSA-OAEP encryption, where an optional parameter is accessed without verification, leading to a NULL pointer dereference and potential application crash. The vulnerability is limited to scenarios involving CMS/S/MIME processing and does not affect all OpenSSL consumers. The advisory does not confirm the availability of a patch or fix for these vulnerabilities but recommends deploying updated container images using the rhui-installer utility and following official documentation. No evidence of memory corruption or code execution is reported, and no known exploits are in the wild.
Potential Impact
The primary impact is a denial-of-service condition caused by a NULL pointer dereference in OpenSSL CMS EnvelopedData processing, which can crash applications that process attacker-controlled CMS data with RSA-OAEP encryption. This affects availability but does not compromise confidentiality or integrity. The vulnerability is considered moderate by Red Hat due to its limited exposure and the niche functionality required to trigger it. No evidence of code execution or memory corruption has been observed. No known active exploitation has been reported.
Mitigation Recommendations
No official fix or patch is explicitly stated in the advisory. Mitigation involves configuring applications that process CMS EnvelopedData messages to accept input only from trusted sources. Additionally, restricting network access to services that handle untrusted CMS data can reduce exposure to this denial-of-service vulnerability. Deploy the updated container images using the rhui-installer utility as recommended by Red Hat and follow the official product documentation for deployment guidance. Monitor Red Hat advisories for updates regarding patches or fixes.
Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
Description
This update includes the following RPMs: gnutls: * gnutls-3.8.13-1.hum1 (aarch64, x86_64) * gnutls-c++-3.8.13-1.hum1 (aarch64, x86_64) * gnutls-dane-3.8.13-1.hum1 (aarch64, x86_64) * gnutls-devel-3.8.13-1.hum1 (aarch64, x86_64) * gnutls-fips-3.8.13-1.hum1 (aarch64, x86_64) * gnutls-utils-3.8.13-1.hum1 (aarch64, x86_64) * mingw32-gnutls-3.8.13-1.hum1 (noarch) * mingw64-gnutls-3.8.13-1.hum1 (noarch) * gnutls-3.8.13-1.hum1.src (src)
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This security advisory from Red Hat addresses multiple vulnerabilities affecting Red Hat Update Infrastructure 5.2 container images, which are based on the latest RHUI RPM packages and ubi9 or ubi9-init base images. Among the referenced CVEs is CVE-2026-28390, a moderate severity denial-of-service vulnerability in OpenSSL. The flaw occurs during processing of Cryptographic Message Syntax (CMS) EnvelopedData messages with RSA-OAEP encryption, where an optional parameter is accessed without verification, leading to a NULL pointer dereference and potential application crash. The vulnerability is limited to scenarios involving CMS/S/MIME processing and does not affect all OpenSSL consumers. The advisory does not confirm the availability of a patch or fix for these vulnerabilities but recommends deploying updated container images using the rhui-installer utility and following official documentation. No evidence of memory corruption or code execution is reported, and no known exploits are in the wild.
Potential Impact
The primary impact is a denial-of-service condition caused by a NULL pointer dereference in OpenSSL CMS EnvelopedData processing, which can crash applications that process attacker-controlled CMS data with RSA-OAEP encryption. This affects availability but does not compromise confidentiality or integrity. The vulnerability is considered moderate by Red Hat due to its limited exposure and the niche functionality required to trigger it. No evidence of code execution or memory corruption has been observed. No known active exploitation has been reported.
Mitigation Recommendations
No official fix or patch is explicitly stated in the advisory. Mitigation involves configuring applications that process CMS EnvelopedData messages to accept input only from trusted sources. Additionally, restricting network access to services that handle untrusted CMS data can reduce exposure to this denial-of-service vulnerability. Deploy the updated container images using the rhui-installer utility as recommended by Red Hat and follow the official product documentation for deployment guidance. Monitor Red Hat advisories for updates regarding patches or fixes.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:20613
- Cve Count
- 13
- Additional Cves
- ["CVE-2026-3833","CVE-2026-5260","CVE-2026-5419","CVE-2026-33845","CVE-2026-33846","CVE-2026-42009","CVE-2026-42010","CVE-2026-42011","CVE-2026-42012","CVE-2026-42013","CVE-2026-42014","CVE-2026-42015"]
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a1df65ee29bf47b5045f308
Added to database: 06/01/2026, 21:15:10 UTC
Last enriched: 08/10/2026, 20:59:57 UTC
Last updated: 09/14/2026, 22:01:33 UTC
Views: 240
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.