Skip to main content
EPSS 0.7%top 47%

Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update

0
High
Published: 05/02/2026 (05/02/2026, 22:26:22 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

This update includes the following RPMs: gnutls: * gnutls-3.8.13-1.hum1 (aarch64, x86_64) * gnutls-c++-3.8.13-1.hum1 (aarch64, x86_64) * gnutls-dane-3.8.13-1.hum1 (aarch64, x86_64) * gnutls-devel-3.8.13-1.hum1 (aarch64, x86_64) * gnutls-fips-3.8.13-1.hum1 (aarch64, x86_64) * gnutls-utils-3.8.13-1.hum1 (aarch64, x86_64) * mingw32-gnutls-3.8.13-1.hum1 (noarch) * mingw64-gnutls-3.8.13-1.hum1 (noarch) * gnutls-3.8.13-1.hum1.src (src)

Affected software

Affected versions
Red HatRed Hat Update InfrastructureRed Hat Update Infrastructure 5amd64registry.redhat.io/rhui5/cds-kubernetes-rhel9@sha256:2958104c085c46561c9453784a06a36ab12a27e21ba1e732b4b30a092bb58805_amd64Red Hat Hardened Imagesaarch64gnutls-main@aarch64Red Hat Enterprise LinuxRed Hat Enterprise Linux AppStream (v. 9)Red Hat Enterprise Linux BaseOS (v. 9)x86_64Red Hat Enterprise Linux AppStream (v. 10)Red Hat Enterprise Linux BaseOS (v. 10)0Red Hat Enterprise Linux AppStream EUS (v. 10.0)Red Hat Enterprise Linux BaseOS EUS (v. 10.0)

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/10/2026, 20:59:57 UTC

Technical Analysis

This security advisory from Red Hat addresses multiple vulnerabilities affecting Red Hat Update Infrastructure 5.2 container images, which are based on the latest RHUI RPM packages and ubi9 or ubi9-init base images. Among the referenced CVEs is CVE-2026-28390, a moderate severity denial-of-service vulnerability in OpenSSL. The flaw occurs during processing of Cryptographic Message Syntax (CMS) EnvelopedData messages with RSA-OAEP encryption, where an optional parameter is accessed without verification, leading to a NULL pointer dereference and potential application crash. The vulnerability is limited to scenarios involving CMS/S/MIME processing and does not affect all OpenSSL consumers. The advisory does not confirm the availability of a patch or fix for these vulnerabilities but recommends deploying updated container images using the rhui-installer utility and following official documentation. No evidence of memory corruption or code execution is reported, and no known exploits are in the wild.

Potential Impact

The primary impact is a denial-of-service condition caused by a NULL pointer dereference in OpenSSL CMS EnvelopedData processing, which can crash applications that process attacker-controlled CMS data with RSA-OAEP encryption. This affects availability but does not compromise confidentiality or integrity. The vulnerability is considered moderate by Red Hat due to its limited exposure and the niche functionality required to trigger it. No evidence of code execution or memory corruption has been observed. No known active exploitation has been reported.

Mitigation Recommendations

No official fix or patch is explicitly stated in the advisory. Mitigation involves configuring applications that process CMS EnvelopedData messages to accept input only from trusted sources. Additionally, restricting network access to services that handle untrusted CMS data can reduce exposure to this denial-of-service vulnerability. Deploy the updated container images using the rhui-installer utility as recommended by Red Hat and follow the official product documentation for deployment guidance. Monitor Red Hat advisories for updates regarding patches or fixes.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:20613
Cve Count
13
Additional Cves
["CVE-2026-3833","CVE-2026-5260","CVE-2026-5419","CVE-2026-33845","CVE-2026-33846","CVE-2026-42009","CVE-2026-42010","CVE-2026-42011","CVE-2026-42012","CVE-2026-42013","CVE-2026-42014","CVE-2026-42015"]
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6a1df65ee29bf47b5045f308

Added to database: 06/01/2026, 21:15:10 UTC

Last enriched: 08/10/2026, 20:59:57 UTC

Last updated: 09/14/2026, 10:01:30 UTC

Views: 239

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

NVD DatabaseMITRE CVEhttps://access.redhat.com/errata/RHSA-2026:26319https://access.redhat.com/products/red-hat-update-infrastructurehttps://access.redhat.com/security/cve/CVE-2026-28390https://access.redhat.com/security/cve/CVE-2026-33845https://access.redhat.com/security/cve/CVE-2026-33846https://access.redhat.com/security/cve/CVE-2026-34180https://access.redhat.com/security/cve/CVE-2026-34181https://access.redhat.com/security/cve/CVE-2026-34182https://access.redhat.com/security/cve/CVE-2026-34183https://access.redhat.com/security/cve/CVE-2026-35177https://access.redhat.com/security/cve/CVE-2026-3832https://access.redhat.com/security/cve/CVE-2026-3833https://access.redhat.com/security/cve/CVE-2026-4046https://access.redhat.com/security/cve/CVE-2026-42009https://access.redhat.com/security/cve/CVE-2026-42010https://access.redhat.com/security/cve/CVE-2026-42011https://access.redhat.com/security/cve/CVE-2026-42012https://access.redhat.com/security/cve/CVE-2026-42013https://access.redhat.com/security/cve/CVE-2026-42014https://access.redhat.com/security/cve/CVE-2026-42015https://access.redhat.com/errata/RHSA-2026:13274https://images.redhat.com/https://access.redhat.com/security/updates/classification/https://access.redhat.com/security/cve/CVE-2026-5260https://access.redhat.com/security/cve/CVE-2026-5419Canonical URLhttps://access.redhat.com/errata/RHSA-2026:20612https://access.redhat.com/security/updates/classification/#important2445763245062424506252467279246728924674372467678Canonical URLhttps://access.redhat.com/errata/RHSA-2026:20613Canonical URLReference 39Reference 40Reference 41Reference 42Reference 4324674412467448246745024674512467686Canonical URLSearch on Google

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses