Skip to main content
EPSS 0.2%top 87%

Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update

0
High
Published: 04/27/2026 (04/27/2026, 18:06:57 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

This update includes the following RPMs: ruff: * python3-ruff-0.15.11-1.hum1 (noarch) * ruff-0.15.11-1.hum1 (aarch64, x86_64) * ruff-0.15.11-1.hum1.src (src)

Affected software

Affected versions
Red HatRed Hat Hardened Imagesnoarchruff-main@noarch

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/16/2026, 17:53:42 UTC

Technical Analysis

This Red Hat security advisory covers a bug fix and enhancement update for Red Hat Hardened Images RPMs, including python3-ruff-0.15.11-1.hum1 and ruff-0.15.11-1.hum1 packages. Among the addressed vulnerabilities is CVE-2026-44029, a directory traversal flaw in Nix's 'nix-prefetch-url --unpack' and 'nix store prefetch-file --unpack' commands, allowing arbitrary file writes. This vulnerability is classified under CWE-36 (Absolute Path Traversal) and can lead to unauthorized code execution, file modification, and denial of service by overwriting critical files. The advisory references multiple CVEs (CVE-2026-41238, CVE-2026-41239, CVE-2026-44028, CVE-2026-44029, CVE-2026-47423) and highlights the high severity of these issues. Red Hat provides updated RPM packages to mitigate these vulnerabilities but does not explicitly list patch availability in the advisory content. The vendor advisory is the authoritative source for remediation.

Potential Impact

The vulnerabilities allow an attacker with local access to perform absolute path traversal during archive unpacking, enabling arbitrary file writes. This can compromise system integrity by overwriting or creating critical files such as programs or libraries, potentially leading to unauthorized code execution or bypass of security mechanisms. Confidentiality may also be impacted if sensitive files are read or overwritten. Additionally, availability can be affected if critical files are corrupted or deleted, potentially causing denial of service. The advisory rates these vulnerabilities as high severity due to their potential to impact integrity and availability significantly.

Mitigation Recommendations

Red Hat has released updated RPM packages (python3-ruff-0.15.11-1.hum1 and ruff-0.15.11-1.hum1) for Red Hat Hardened Images to address these vulnerabilities. Users should apply these updates as soon as possible by following the instructions at https://images.redhat.com/. No additional mitigations or workarounds are specified in the advisory. Patch status is confirmed by the vendor advisory indicating updated packages are available.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:10999
Cve Count
4
Additional Cves
["CVE-2026-41239","CVE-2026-44028","CVE-2026-44029"]
State
PUBLISHED

Threat ID: 6a54ae1068715ace438f8d1e

Added to database: 07/13/2026, 09:21:20 UTC

Last enriched: 08/16/2026, 17:53:42 UTC

Last updated: 09/14/2026, 10:01:30 UTC

Views: 60

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses