Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
This update includes the following RPMs: glibc: * compat-libpthread-nonshared-2.42-12.hum1 (aarch64, x86_64) * glibc-2.42-12.hum1 (aarch64, x86_64) * glibc-all-langpacks-2.42-12.hum1 (aarch64, x86_64) * glibc-benchtests-2.42-12.hum1 (aarch64, x86_64) * glibc-common-2.42-12.hum1 (aarch64, x86_64) * glibc-devel-2.42-12.hum1 (aarch64, x86_64) * glibc-doc-2.42-12.hum1 (noarch) * glibc-gconv-extra-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-aa-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-af-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-agr-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-ak-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-am-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-an-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-anp-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-ar-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-as-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-ast-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-ayc-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-az-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-be-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-bem-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-ber-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-bg-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-bhb-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-bho-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-bi-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-bn-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-bo-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-br-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-brx-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-bs-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-byn-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-ca-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-ce-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-chr-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-ckb-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-cmn-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-crh-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-cs-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-csb-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-cv-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-cy-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-da-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-de-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-doi-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-dsb-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-dv-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-dz-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-el-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-en-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-eo-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-es-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-et-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-eu-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-fa-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-ff-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-fi-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-fil-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-fo-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-fr-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-fur-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-fy-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-ga-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-gbm-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-gd-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-gez-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-gl-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-gu-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-gv-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-ha-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-hak-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-he-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-hi-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-hif-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-hne-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-hr-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-hsb-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-ht-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-hu-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-hy-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-ia-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-id-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-ig-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-ik-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-is-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-it-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-iu-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-ja-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-ka-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-kab-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-kk-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-kl-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-km-2.4
AI Analysis
Technical Summary
The vulnerability (CVE-2026-5435) exists in glibc's deprecated TSIG record printing functions, which fail to properly manage memory buffers, resulting in an out-of-bounds write. This buffer overflow (CWE-120) can be triggered by processing maliciously crafted TSIG records, potentially leading to denial of service or arbitrary code execution. Red Hat has released updated RPM packages for glibc and related components in Red Hat Hardened Images to address this flaw. The advisory notes that Red Hat's CVSS score differs from other sources due to product-specific factors. No known exploits are reported in the wild at this time.
Potential Impact
The vulnerability can lead to denial of service by crashing affected applications or systems. Additionally, it may allow an attacker to execute arbitrary code, compromising system integrity and confidentiality. The impact is rated medium by Red Hat, reflecting the potential for both availability disruption and code execution. There are no reports of active exploitation in the wild.
Mitigation Recommendations
Red Hat has released updated RPM packages for glibc and related components as part of the Red Hat Hardened Images update. Users should apply these official patches promptly to remediate the vulnerability. No alternative mitigations or workarounds are indicated in the advisory. Patch status is confirmed by the vendor advisory.
Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
Description
This update includes the following RPMs: glibc: * compat-libpthread-nonshared-2.42-12.hum1 (aarch64, x86_64) * glibc-2.42-12.hum1 (aarch64, x86_64) * glibc-all-langpacks-2.42-12.hum1 (aarch64, x86_64) * glibc-benchtests-2.42-12.hum1 (aarch64, x86_64) * glibc-common-2.42-12.hum1 (aarch64, x86_64) * glibc-devel-2.42-12.hum1 (aarch64, x86_64) * glibc-doc-2.42-12.hum1 (noarch) * glibc-gconv-extra-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-aa-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-af-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-agr-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-ak-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-am-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-an-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-anp-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-ar-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-as-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-ast-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-ayc-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-az-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-be-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-bem-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-ber-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-bg-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-bhb-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-bho-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-bi-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-bn-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-bo-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-br-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-brx-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-bs-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-byn-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-ca-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-ce-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-chr-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-ckb-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-cmn-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-crh-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-cs-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-csb-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-cv-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-cy-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-da-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-de-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-doi-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-dsb-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-dv-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-dz-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-el-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-en-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-eo-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-es-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-et-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-eu-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-fa-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-ff-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-fi-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-fil-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-fo-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-fr-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-fur-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-fy-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-ga-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-gbm-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-gd-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-gez-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-gl-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-gu-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-gv-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-ha-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-hak-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-he-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-hi-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-hif-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-hne-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-hr-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-hsb-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-ht-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-hu-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-hy-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-ia-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-id-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-ig-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-ik-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-is-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-it-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-iu-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-ja-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-ka-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-kab-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-kk-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-kl-2.42-12.hum1 (aarch64, x86_64) * glibc-langpack-km-2.4
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability (CVE-2026-5435) exists in glibc's deprecated TSIG record printing functions, which fail to properly manage memory buffers, resulting in an out-of-bounds write. This buffer overflow (CWE-120) can be triggered by processing maliciously crafted TSIG records, potentially leading to denial of service or arbitrary code execution. Red Hat has released updated RPM packages for glibc and related components in Red Hat Hardened Images to address this flaw. The advisory notes that Red Hat's CVSS score differs from other sources due to product-specific factors. No known exploits are reported in the wild at this time.
Potential Impact
The vulnerability can lead to denial of service by crashing affected applications or systems. Additionally, it may allow an attacker to execute arbitrary code, compromising system integrity and confidentiality. The impact is rated medium by Red Hat, reflecting the potential for both availability disruption and code execution. There are no reports of active exploitation in the wild.
Mitigation Recommendations
Red Hat has released updated RPM packages for glibc and related components as part of the Red Hat Hardened Images update. Users should apply these official patches promptly to remediate the vulnerability. No alternative mitigations or workarounds are indicated in the advisory. Patch status is confirmed by the vendor advisory.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:12740
- Cve Count
- 5
- Additional Cves
- ["CVE-2026-5435","CVE-2026-5450","CVE-2026-5928","CVE-2026-6238"]
- State
- PUBLISHED
Threat ID: 6a160976e29bf47b506413c6
Added to database: 05/26/2026, 20:58:30 UTC
Last enriched: 08/16/2026, 16:25:17 UTC
Last updated: 09/12/2026, 22:01:34 UTC
Views: 120
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.